XakNet

Threat Actor updated 5 months ago (2024-05-04T18:17:27.068Z)
Download STIX
Preview STIX
XakNet is a notable threat actor, potentially aligned with Russian interests, that has been implicated in various cyber attacks. This group emerged prominently during Russia's conflict with Ukraine and the subsequent ban on Russia from the 2022 FIFA World Cup. The Russian government was suspected of encouraging or tacitly approving disruptive attacks by nationalistic Russian "hacktivist" groups like XakNet. These groups served as useful proxy forces to further Russia's strategic objectives while providing plausible deniability. In 2023, XakNet was identified as one of the most active Russian Advanced Persistent Threats (APTs), indicating its significant cyber capabilities. This group, along with others such as KillNet and Cyber Army of Russia, have been linked to information operations against Western organizations and entities. Their activities are likely aimed at stoking fear or decreasing support for Ukraine. Notably, XakNet launched a distributed denial-of-service (DDoS) attack on the Israeli parliament's website in retaliation for Israel providing intelligence information on Iranian drones to Ukraine. These actions demonstrate XakNet's willingness to target high-profile entities and its capability to execute complex cyber attacks. The increasing activity of pro-Russian hacktivist groups like XakNet is a response to the sanctions imposed on Russia and other support provided by the U.S. and its allies to Ukraine. Most of their activities consist of Distributed Denial-of-Service (DDoS) attacks. Researchers have suggested that these groups, including XakNet, act as fronts to share information obtained illegally by state-backed groups, further highlighting their potential ties to Russian security services. Given their demonstrated capabilities and aggressive tactics, XakNet and similar groups represent a significant cyber threat.
Description last updated: 2024-05-04T17:41:55.722Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Cyber Army of Russia is a possible alias for XakNet. The Cyber Army of Russia (CAR), a threat actor group, has been a significant source of cyber threats since 2022. This group, believed to be linked with the notorious Sandworm hacking team, has launched a series of low-impact Distributed Denial of Service (DDoS) attacks against entities in Ukraine an
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Russia
Ddos
Ukraine
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The KillNet Threat Actor is associated with XakNet. Killnet is a pro-Russian threat actor group that has gained notoriety for its disruptive cyber-attacks on various government entities. The group's activities peaked in July 2022 when it targeted multiple government resources in Poland, including the Ministry of Foreign Affairs, Senate, Border Controis related to
3