CSIDB logo
Threat actor

rootkitsecurity

Attribution profile

Type
Activist
Location
Ukraine
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-01 01:56
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

rootkitsecurity is an alias used by a threat actor that has been identified as operating from Ukraine. The actor describes itself as part of the pro‑Ukraine hacktivist community and has expressed cooperation with the broader international community in its statements. Public reporting links the alias to a series of statements made on Telegram and Twitter that condemn Iranian support for Russia’s invasion of Ukraine. No public source has identified a state sponsor or criminal organization backing the actor. The alias first appeared in public discourse in December 2022, coinciding with a surge of pro‑Ukraine cyber activity after Iranian‑supplied drones were used in attacks on Ukraine.

The actor’s observed activity focuses on disrupting online services belonging to Iranian governmental and critical‑infrastructure entities. Targets mentioned in open sources include the website of Iran’s supreme leader, the National Iranian Oil Company, Iran’s central bank, domestic messaging applications such as Rubika and Bale, and Iran Airlines’ online services. The stated strategic objective is to impose a cost on Iran for its provision of drones to Russia, with the actor warning that each military bombardment will be met with a cyberattack on Iranian infrastructure. The primary technique described is a distributed denial‑of‑service attack that floods victim networks with fake traffic to render them temporarily unavailable. No reference to malware families, exploit kits, or specific intrusion tools appears in the reported material.

Representative operations attributed to rootkitsecurity include a claim of launching DDoS attacks on the supreme leader’s website and the National Iranian Oil Company on New Year’s Day 2022, coinciding with Ukrainian air‑defense actions against Iranian‑supplied drones. The actor also posted a tweet asserting that Iran Airlines’ online services had stopped working properly due to its attack, using hashtags associated with the #OpIran and #MashaAmini campaigns. The actor’s Twitter post included a screenshot purporting to show the disrupted Iran Airlines service, reinforcing the claim of operational effect. In early January 2023 Iranian officials reported having repelled a wave of DDoS attempts against the country’s central bank and domestic messaging apps, a development that aligns with the actor’s stated intent to continue pressure until Iran ceases drone shipments to Russia. These incidents constitute the publicly known campaigns linked to the alias.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB