RaHDIt
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
RaHDIt is a hacker group known by that alias and is based in Russia. The group first came to public attention through the release of data concerning Ukrainian intelligence services. In September 2022 they published personal and operational details of approximately 1,500 employees of the Ukrainian foreign intelligence service. The disclosed information included officers serving under diplomatic cover in embassies across more than twenty nations. It also covered personnel working in the missions of the United Nations, the European Union and NATO. Additionally, the leak revealed the locations of over forty units of the Ukrainian SVR, among them a clandestine educational institution.
Prior to the September 2022 release, RaHDIt had already exposed data belonging to thousands of members of Ukraine’s Main Intelligence Directorate (GUR). That earlier disclosure identified embassy residencies of GUR officers in countries such as India, Russia, Italy, Turkey, Iran, Austria, Vietnam and South Africa. Together these incidents show a consistent focus on Ukrainian military and foreign intelligence structures. The targeted sectors are therefore intelligence, diplomatic representation and international organizations. The geographic scope of the exposed personnel spans Europe, North America, Asia and Africa. The releases exposed operational details and cover identities of intelligence officers stationed abroad.
RaHDIt’s observable tactic involves exfiltrating sensitive datasets and subsequently posting them on a website for public consumption. No specific malware families, exploit kits or intrusion tools are described in the available reporting. The group’s activity is limited to the acquisition and dissemination of information rather than financial gain or destructive disruption. Attribution in open sources notes the group’s Russian location but does not assert a formal state sponsor or criminal‑consortium link. The two major leaks described above constitute the most prominent campaigns publicly attributed to RaHDIt to date.
Incidents
Attributed incidents are available to members.
1 incident