logo

Pro-Russian Hacktivists Targeting Adversaries With Killnet

ID: abbefafd-fb03-5827-af5b-4940294c4f6f

STIX ID: report--abbefafd-fb03-5827-af5b-4940294c4f6f

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-21

Date Updated: 2026-07-16

...
...

This report analyzes a destructive Killnet ransomware sample (SHA256 db1c8ddcdfea9...) attributed to the pro‑Russian Killnet hacktivist group: it documents persistence via a dropped cmd.exe in AppData and a startup shortcut, privilege escalation (runas), deletion of shadow copies/backups, targeted encryption of many file types with a ".killnet" extension, desktop lock/notice, and includes IOCs and mitigation recommendations; the actors also solicit funds and propaganda via a large Telegram channel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.