Killnet — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Killnet

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Killnet
    🏴
    Hacktivist collective logo (illustrative)
    Also known asLegion · Rayd · Zarya
    Formationc. January 2022
    TypeHacktivist collective
    PurposeDDoS, Psychological operations
    Target SectorsGovernment, Healthcare, Aviation, Logistics
    Alleged parent org.State-aligned (independent)
    Attribution confidenceHigh
    Status● Active
    Notable tacticsDDoS, Telegram orchestration

    Killnet is a pro-Russian hacktivist collective that gained prominence shortly before the 2022 invasion of Ukraine. Furthermore, the group is primarily recognized for its large-scale Distributed Denial of Service (DDoS) campaigns. These attacks target Western government agencies and critical infrastructure websites.[1]

    Unlike state-sponsored APT groups that prioritize stealth, Killnet seeks maximum public visibility. The group uses social media platforms like Telegram to coordinate volunteers and announce its successes. Consequently, their operations often serve as a form of psychological warfare against nations supporting Ukraine.[2]

    Aliases and Sub-groups:
    Legion (Volunteer arm) · Rayd · Zarya · Ms. Killnet

    Overview

    Killnet emerged in early 2022, initially claiming to be a DDoS-for-hire service. However, they quickly pivoted to political hacktivism following the escalation of the Russia-Ukraine conflict. The group maintains a highly vocal presence on Telegram, where they recruit supporters and share propaganda.[1]

    Group Structure

    The collective operates through a decentralized network of smaller groups. For instance, the “Legion” serves as their primary volunteer force. These sub-groups often compete or collaborate on specific targets. In addition, the group maintains a hierarchy led by a persona known as “KillMilk.”[3]

    “Killnet represents a shift in modern conflict. They combine basic technical attacks with highly effective social media orchestration to create a sense of digital chaos.”
    — Cybersecurity Trend Analysis, 2023[4]

    Targets and Victimology

    Killnet focuses on organizations within NATO and EU countries. Their targets generally include:

    • Government Portals — Websites of ministries, parliaments, and local governments.
    • Healthcare — Hospitals and medical research centers in the UK and USA.
    • Aviation — Major international airports and flight booking systems.
    • Financial Services — National banks and payment processing networks.

    Attack Methodologies

    The group relies on volume-based attacks to overwhelm servers. While these attacks are technically simple, they can cause significant operational downtime.

    TechniqueDescription
    DDoS (T1498)Overwhelming web servers with massive amounts of junk traffic.
    DefacementAltering the visual appearance of websites to display pro-Russian messages.
    Social EngineeringUsing Telegram to incite followers to perform “stress testing” on targets.

    Notable Campaigns

    DateCampaignImpact
    May 2022Eurovision Song ContestUnsuccessful attempt to disrupt the voting systems.
    Oct 2022U.S. AirportsBriefly disabled websites of several major U.S. airports.
    Jan 2023European HospitalsCoordinated attacks on dozens of medical facilities.
    2024NATO InfrastructureSustained targeting of logistical support websites.

    Psychological Impact

    Although Killnet’s technical impact is often temporary, their psychological influence is notable. By taking down visible public websites, they create a perception of vulnerability. Furthermore, their rapid communication on Telegram ensures that even minor disruptions receive international media coverage.[2]

    References

    1. Flashpoint, “A Deep Dive into Killnet” (2022).
    2. Mandiant, “Pro-Russian Hacktivism and the War in Ukraine” (2023).
    3. CISA, “Stop-DDoS: Lessons from Recent Hacktivist Campaigns” (2023).
    4. Radware, “Killnet: The Hacktivist Group Challenging NATO” (2023).
    Categories: Hacktivism · Pro-Russian Hacking · DDoS · Cyberwarfare · Telegram Communities
    This page was last updated August 2026. Content reflects public observations of hacktivist activity.