CSIDB logo
Threat actor

Main Intelligence Directorate (HUR)

Attribution profile

Type
Nation State
Location
Ukraine
Known incidents
8 incidents
First seen
2023-11-28
Last seen
2025-07-17
Updated
2026-07-22 00:13
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is publicly identified by the aliases Main Intelligence Directorate (HUR) and HUR. Open‑source reporting describes it as Ukraine’s military intelligence directorate. The actor’s base location is noted as Ukraine in the provided material. Its activities are consistently attributed to the Ukrainian state’s military intelligence service. No alternative names or affiliations are mentioned in the sources. The actor’s public persona is tied to Ukraine’s defense and intelligence apparatus. No criminal or commercial connections are described. These points constitute the basic overview of the actor.

The actor has directed operations against Russian energy firms such as Gazprom and Lukoil. Telecommunications providers including MegaFon, Yota, NetByNet, Rostelecom, MTC, Beeline and Yandex have also been targeted. Financial institutions hit include Gazprombank and several major Russian banks. Government services struck comprise the Russian Federal Taxation Service. Military‑related industrial facilities that produce law‑enforcement, aviation and ballistic‑protection equipment have been attacked. Communications platforms used by military and intelligence personnel, such as WhatsApp and Telegram, have suffered service outages attributed to the actor. Hydrometeorological research centers that support Russian military satellite services have been subjected to destructive cyber operations. Observed effects include wiping databases, destroying SCADA and 1C server clusters, disabling administrator access, damaging BIOS firmware and erasing operating systems from hundreds of servers. Distributed denial‑of‑service attacks have disrupted online services and payment systems. The actor’s actions have resulted in ATM failures, card‑payment blocks, mobile‑banking outages and interruptions to public‑transport fare systems and telecommunications. These outcomes demonstrate a strategic focus on causing operational disruption and destruction. The source material does not contain explicit statements about financial gain or intelligence‑collection motives.

The actor’s tradecraft involves gaining initial network access before deploying destructive payloads. Malware used in the attacks is designed to wipe data, delete backups and corrupt configuration files. In several incidents the malware also damaged BIOS or firmware, rendering hardware inoperable. Distributed denial‑of‑service traffic has been employed to overwhelm telecom and online‑service infrastructure. Attacks on supervisory control and data acquisition (SCADA) systems and industrial control environments have been reported. Financial‑sector intrusions have targeted payment‑processing systems, ATM networks and mobile‑banking platforms. Government‑sector intrusions have breached taxation‑service servers and regional nodes, disabling inter‑office communications. Military‑focused operations have compromised drone‑control software, removing video‑streaming and identification functions and forcing manual operation. Attacks on hydrometeorological research centers have erased petabytes of satellite data and destroyed hundreds of servers. The actor has also deleted operating systems from large numbers of servers after exfiltrating terabytes of data. No specific malware families, exploit kits or phishing techniques are named in the provided sources. The described techniques consistently emphasize destructive impact and service denial. Representative campaigns include the July 2025 Gazprom network wipe, the March 2025 Lukoil IT‑network outage, the January 2025 MegaFon DDoS that disrupted mobile and internet services, the December 2024 Gazprombank DDoS affecting online banking, the July 2024 sustained financial‑institution campaign causing ATM and payment‑system failures, the November 2023 Federal Taxation Service breach that destroyed databases and backups, the January 2024 hydrometeorology‑center attack that erased two petabytes of satellite data, and the 2024 large‑scale assault on Russian internet providers and military‑related industrial facilities. These incidents illustrate a pattern of disruptive, destructive cyber operations aimed at Russian critical infrastructure and military‑supporting sectors. No additional campaigns beyond those described are referenced in the source material. The actor’s public record consists of the disruptive actions outlined above.

Incidents

Attributed incidents are available to members.

8 incidents
CSIDB