Killnet
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Killnet is a pro‑Russian hacktivist group that has operated under the alias Killnet since emerging after Russia’s February 2022 invasion of Ukraine. The group is known to communicate and claim responsibility for its actions via Telegram channels, where it posts screenshots, links to alleged stolen data, and statements framing its attacks as retaliation against nations that support Ukraine. Open‑source reporting places the group’s origin in Russia, although no definitive public evidence links it directly to a specific Russian state institution.
Killnet’s observed activity centers on distributed denial‑of‑service (DDoS) attacks aimed at disrupting online services rather than achieving financial gain or sustained espionage. The group has targeted a wide range of sectors, including telecommunications (Ukraine’s Kyivstar operator), government portals (U.S. state websites in Colorado, Kentucky and Mississippi; Bulgarian ministries; Latvian and Lithuanian parliaments), transportation infrastructure (major U.S. airports such as Atlanta Hartsfield‑Jackson and Los Angeles International; European air‑traffic agency Eurocontrol), financial institutions (U.S. Treasury, JPMorgan Chase, European Investment Bank), and media or royal family sites (British royal family website, Prince of Wales site). In several incidents Killnet has also asserted data theft, claiming to have obtained employee personally identifiable information from Lockheed Martin and credentials from the U.S. Federal Motor Carrier Safety Administration, though these claims have not been independently verified. The group’s typical tooling consists of DDoS flooding techniques, occasional phishing lures (as seen in Moldova), and the use of compromised social media accounts to demonstrate access, as shown when it posted to a Federal Motor Carrier Safety Administration employee’s Facebook profile.
Public attribution of Killnet remains uncertain; while researchers describe it as a Kremlin‑aligned hacktivist collective, the sources repeatedly note that ties to Russian state entities are unconfirmed. The group’s campaigns are consistently framed as politically motivated, with statements linking attacks to geopolitical events such as the delivery of Leopard 2 tanks to Ukraine, the recognition of Russia as a state sponsor of terrorism by the European Parliament, and NATO’s support for Ukrainian forces. Notable operations include the December 2023 DDoS‑related outage of Kyivstar that disrupted mobile service and air‑raid alert systems, the October 2023 attack on the British royal family website, the June 2023 DDoS incident against the European Investment Bank, and the repeated targeting of U.S. government and airport sites throughout 2022. These actions illustrate Killnet’s pattern of using high‑volume traffic to temporarily knock services offline, seeking publicity and perceived strategic impact without asserting persistent access or data exfiltration that has been substantiated.
Incidents
Attributed incidents are available to members.
14 incidents