Just Evil/Kill Milk
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Just Evil/Kill Milk is a threat actor that operates under the aliases Just Evil and Kill Milk and is known to be based in Russia. The group is reportedly led by an individual named Nikolai Serafimov, according to public sources. These identifiers are the only personal details that have been explicitly linked to the actor in the available information.
The actor’s most clearly documented operation occurred on May 19 2024 when it targeted Hamburg Airport’s IT infrastructure. The group claimed to have gained unauthorized access to secured areas and shared screenshots of a control panel and surveillance camera feeds as proof. Hamburg Airport officials confirmed that the breach affected an externally hosted system used for monitoring security patrol documentation, which was isolated from the airport’s core operations. They stated that no safety‑critical data were compromised and that air traffic was not disrupted as a result of the incident. The group’s assertions of data exfiltration were not substantiated by the airport’s investigation.
Attribution to Just Evil/Kill Milk includes the alleged leadership of Nikolai Serafimov and a noted connection to distributed denial‑of‑service activities and earlier geopolitical cyber campaigns. No specific malware families, initial‑access vectors, or tooling styles have been publicly referenced in relation to this actor. Consequently, the profile is limited to the confirmed facts of the aliases, the Russian location, the alleged leader, the Hamburg Airport incident, and the stated linkages to DDoS and prior geopolitical operations. No further details about their capabilities, objectives, or internal structure can be derived from the supplied sources.
Incidents
Attributed incidents are available to members.
1 incident