Menu
Browse

0v1ru$

Primary URL Location Industry
Undetermined
Country Russia
Government - National Icon
Government - National
Profile

0v1ru$ is a hacking group that carries out cyber intrusions against organisations linked to Russian state security. The group gained public attention after compromising SyTech, a contractor for Russia's primary security agency, in July 2019. During the breach they exfiltrated internal documents detailing several projects, including social media scraping tools aimed at platforms such as Facebook and LinkedIn. The stolen material also covered efforts to de‑anonymize Tor browser users and preparatory work for a sovereign Russian internet infrastructure. After obtaining the data, 0v1ru$ shared it with the broader hacking collective known as Digital Revolution and subsequently leaked it to media outlets. In addition to data theft, the attackers defaced SyTech’s public website to mock the agency’s security posture.

The incident highlighted the group’s focus on penetrating the intelligence supply chain by targeting third‑party contractors rather than the agency directly. Their operations are distinguished by an interest in capabilities that monitor online speech and anonymity networks, as evidenced by the exposed social media scraping and Tor de‑anonymization projects. Collaboration with Digital Revolution suggests a willingness to operate within a loose network of hacktivist‑aligned actors rather than as an isolated entity. The website defacement served both as a demonstration of technical access and as a propaganda act intended to embarrass the victim organisation. Analysts described the SyTech breach as potentially the largest in the history of the Russian security agency’s contractor ecosystem. 0v1ru$ is characterised by its selective targeting of state‑linked contractors, its disclosure of sensitive technical projects, and its use of both data leaks and public defacement to achieve impact.

Incidents
Linked incidents available to members
1 incident