Home/Threat Actor/IT Army of Ukraine
Threat Actor

IT Army of Ukraine

it_army_ukraine · ukraine_government_volunteer_offensive_operations · active since 2022-02

IT Army of Ukraine (canonical English naming) is a Ukrainian volunteer hacktivist collective officially launched February 26, 2022 by Minister of Digital Transformation Mykhailo Fedorov 2 days after Russian invasion of Ukraine via Telegram channel call to arms, first time any government official has publicly called on volunteer hackers to attack another country's infrastructure per Foreign Policy ("Ukrainian Vice Prime Minister Mykhailo Fedorov took a step no other government official in the world likely ever has: He publicly called on volunteer hackers to take down another country's websites. And he had a list of 31 Russian government, bank, and corporation websites ready to go. Within days, Ukraine had amassed an 'IT army' of more than 400,000 volunteers")

Ukrainian government partial-association attribution via Fedorov founding + 25-30 Generals from Ukrainian government agencies coordinating Colonels-level technical operators per CEPA October 2024 + non- public attacks showing intelligence-services coordination per Stefan Soesanto Center for Security Studies Zurich 32-page analysis, with both group + Ukrainian Ministry of Digital Transformation officially claiming cooperation hasn't extended beyond initial establishment + Ted canonical IT Army spokesperson 2023-2024 interviews describing legal grey-area status + CyberPeace Institute Geneva 92-cyberattack neutral-third- party operational tracking + CSIS Strategic Technologies Blog + Foreign Policy + The Record + Euromaidan Press + Kyiv Independent + CyberScoop + New Eastern Europe industry coverage.

standalone cluster paralleling predatory_sparrow + cyber_partisans + ghostsec in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

operational target profile Russian government websites primary + Russian state media + Russian banking system (Gazprombank November 2022 + June 20, 2024 "largest DDoS attack in history") + Russian corporate Top-100 (April 2024 Russian media: almost half lack professional Layer 7 DDoS protection) + Russian airline + transit (Leonardo airline booking system disrupting Russian major airports) + Russian oil/ gas/energy (10x DDoS increase year-over-year per Russian media May 2024) + Russian St. Petersburg International Economic Forum June 2024 + Russian Kremlin + Foreign Ministry + Stock Exchange + principal security agency.

operational attack architecture: (1) cluster-defining Mykhailo Fedorov ministerial call-to-arms unprecedented founding event February 26, 2022 with Telegram channel ballooning to 300,000 members by March 2022 and 400,000 volunteers within days.

(2) cluster-defining DDoS democratization primary tradecraft with GitHub-hosted tools + cloud- hosted volunteer-run VPSs + accessible Layer 4 + Layer 7 Application Exhaustion Flood capabilities per CSIS + Kyiv Independent.

(3) cluster-defining Telegram channel target lists daily distribution operational signature with at least 662 Russian targets listed over time per Soesanto research; (4) cluster-defining June 20, 2024 "largest DDoS attack in history" against Russia banking system crippling numerous banks demonstrating sustained capability 2+ years into Russia-Ukraine war.

(5) cluster-defining Leonardo airline booking system attack with significant DDoS leading to substantial disruptions at Russia's major airports (Fedorov: "If Ukrainian airports cannot operate because of the war, why should Russian ones?")

(6) signature Gazprombank November 2022 attack with attackers knowing entire pool of bank's IP addresses including those not involved in banking services demonstrating beyond-typical-hacktivist reconnaissance sophistication.

(7) cluster- defining 25-30 Generals from Ukrainian government agencies + Colonels-level high-level-hackers hierarchical organizational structure per CEPA; (8) signature 50 core executive team + 3,000- 10,000 active volunteers ongoing + Ted public spokesperson media presence providing operational continuity per Euromaidan Press + The Record.

(9) signature Yegor Aushev defensive Ukrainian IT Corp parallel with 1,000-1,500 specialists protecting Ukrainian critical infrastructure establishing distinct defensive-vs-offensive operational division per CSIS.

(10) cluster- defining legal grey-zone status within Ukraine (IT Army not recognized as legal entity, activities punishable even under local laws) + potential Estonia-style cyber-reserve evolution consideration per The Record signature unique legal framework.

cluster fills the February-2022- onward-Ukrainian-volunteer-offensive-operations + Mykhailo-Fedorov-ministerial-call-to-arms + 300000-400000-volunteer-mobilization + DDoS-russia- government-banks-media-corporate + Leonardo-airline- booking-system-airport-disruption + June-2024- largest-ddos-attack-history-banking + 25-30- Generals-Colonels-organizational-structure + CyberPeace-Institute-92-attacks-documented + legal-grey-zone-status position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

canonical illustration of government- minister-launched hacktivist mobilization + unprecedented public-call-to-arms by sitting government official + 300,000+ volunteer scale DDoS democratization + Layer 7 evolved capability + Generals-Colonels hierarchical coordination + legal-grey-zone status + Yegor-Aushev-parallel- defensive-corp + Russia-Ukraine war cyber mobilization cited in essentially all subsequent Russia-Ukraine war cyber industry analyses through 2022-2026 period.

ukraine_government_volunteer_offensive_operations confidence: high 21 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

IT Army of Ukraine (canonical English naming) is a Ukrainian volunteer hacktivist collective officially launched February 26, 2022 by Minister of Digital Transformation Mykhailo Fedorov 2 days after Russian invasion of Ukraine via Telegram channel call to arms, first time any government official has publicly called on volunteer hackers to attack another country's infrastructure. Ukrainian government partial-association attribution via Fedorov founding call + 25-30 Generals from Ukrainian government agencies coordinating Colonels-level technical operators per CEPA + non- public attacks showing intelligence-services coordination per Stefan Soesanto Center for Security Studies analysis. Both group + Ukrainian Ministry of Digital Transformation officially claim cooperation hasn't extended beyond initial establishment.

Standalone cluster paralleling predatory_sparrow + cyber_partisans + ghostsec in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

Operational target profile
  • Russian government websites primary.
  • Russian state media primary.
  • Russian banking signature.
  • Russian airline + transit signature.
  • Russian corporate Top-100 secondary.
  • Russian oil/gas/energy secondary.
  • Russian international economic forums secondary Operational attack architecture: (1) Fedorov ministerial call-to-arms founding (cluster-defining): unprecedented public call mobilizing 300,000-400,000 volunteers within days (2) DDoS democratization primary tradecraft (cluster-defining): GitHub-hosted tools + cloud- hosted via volunteer VPSs + accessible Layer 4 + Layer 7 application exhaustion flood capabilities (3) Telegram channel target lists daily distribution (cluster-defining): 662+ Russian targets listed over time per Soesanto (4) June 20, 2024 "largest DDoS attack in history" against Russia banking signature operation (5) Leonardo airline booking system attack (cluster-defining): kinetic-effect transportation infrastructure disruption (6) Gazprombank entire-IP-pool sophisticated reconnaissance + targeting capability (signature): Nov 2022 demonstrating beyond-typical-hacktivist sophistication (7) 25-30 Generals + Colonels hierarchical organizational structure (cluster-defining) (8) 50 core executive team + 3000-10000 active volunteers + Ted public spokesperson media presence (signature) (9) Yegor Aushev defensive parallel ~1000-1500 specialists Ukrainian IT Corp (signature) (10) Legal grey-zone status + potential cyber reserve evolution consideration (signature) The cluster fills the February-2022-onward-Ukrainian- volunteer-offensive-operations + Mykhailo-Fedorov- ministerial-call-to-arms + 300000-400000-volunteer- mobilization + DDoS-russia-government-banks-media- corporate + Leonardo-airline-booking-system-airport- disruption + June-2024-largest-ddos-attack-history- banking + 25-30-Generals-Colonels-organizational- structure + CyberPeace-Institute-92-attacks- documented position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

Aliases

21
it_army_ukraineit army of ukraineit army ukraineitarmy_ukraineukraine it armyukraine volunteer it armyit army ukraine fedorov 26 february 2022 launchit army ukraine ministry of digital transformationit army ukraine mykhailo fedorov telegram channelit army ukraine 300000 telegram members peak march 2022it army ukraine 400000 volunteers within daysit army ukraine ddos russian government infrastructureit army ukraine june 2024 largest ddos attack history russia bankingit army ukraine leonardo airline booking system russian airportsit army ukraine gazprombank november 2022 attackit army ukraine 25-30 generals colonels organizational structureit army ukraine ted spokesperson interviewsit army ukraine cyberpeace institute geneva 92 attacks documentedit army ukraine 1 billion damage russia volunteer hackersit army ukraine github ddos tools terms of service violationit army ukraine yegor aushev defensive 1000 specialists parallel

Notable Campaigns

12
2024IT Army of Ukraine Leonardo Airline Booking System Attack, Russian Airports Disruption
2024IT Army of Ukraine June 20 2024 'Largest DDoS Attack in History' Against Russia Banking System
2024IT Army of Ukraine St. Petersburg International Economic Forum DDoS June 2024
2024IT Army of Ukraine Russian Top-100 Corporations + Layer 7 DDoS Targeting (2024)
2022-2026Continued Industry Reference Status (2022-2026)
2022-2024IT Army of Ukraine 25-30 Generals + Colonels Organizational Structure
2022-2024CyberPeace Institute Geneva 92 Attacks Documented (2022-2024)
2022-2024IT Army of Ukraine Legal Grey-Area Status + Ukraine Cyber Reserve Consideration
2022-2024Yegor Aushev Defensive Ukrainian IT Corp Parallel (~1,000-1,500 Specialists)
2022IT Army of Ukraine Origin, Mykhailo Fedorov Call to Arms (February 26, 2022)
2022IT Army of Ukraine Opening Salvo, Russian Foreign Ministry + Stock Exchange + State Bank (February 2022)
2022IT Army of Ukraine Gazprombank November 2022 Attack

Attribution & Reporting

Attributed by
CSIS Strategic Technologies Blog (canonical August 2023 The IT Army of Ukraine analysis)Foreign Policy (canonical April 2022 Ukraine's IT Army of Hackers Take the Fight to Russia)The Record / Recorded Future News (canonical April 2024 IT Army coordinated machine + Ted spokesperson interview + CyberPeace Institute 92-attack tracking)Euromaidan Press (canonical January 2024 How Ukraine built a volunteer hacker army from scratch + Ted interview)CEPA (canonical October 2024 Ukraine Volunteer IT Army Confronts Tech Legal Challenges + 25-30 Generals + Leonardo attack)CyberScoop (canonical Stefan Soesanto research + ministry distance + IT Army interactions)New Eastern Europe (canonical July 2024 Ukraine's IT hacker army requires non-technical solution to scale)Kyiv Independent (canonical July 2024 Ukraine's volunteer hacker army is pioneering new era of cyber warfare)Mykhailo Fedorov / Ukrainian Minister of Digital Transformation (canonical Feb 26 2022 founding call + ongoing operational reporting)Stefan Soesanto / Center for Security Studies Zurich (canonical 32-page IT Army analysis paper)Ted (canonical IT Army spokesperson 2023-2024 interviews via The Record + Euromaidan Press)Yegor Aushev (canonical defensive Ukrainian IT Corp parallel ~1000-1500 specialists)CyberPeace Institute Geneva (canonical 92-attack tracking research)Vasily Nebenzya / Permanent Representative of Russia to UN (canonical Russian government attribution acknowledgment)Victor Zhora / SSSCIP Deputy Chairman (canonical Ukrainian government distance/gratitude statements)Alex Holden / Hold Security (canonical commentary on participant-country implications)Vasileios Karagiannopoulos / University of Portsmouth (canonical modern hacktivism evolution assessment)
Key reporting
reportCSIS Strategic Technologies Blog: The IT Army of Ukraine (August 2023), canonical analysis
reportForeign Policy: Ukraine's 'IT Army' of Hackers Take the Fight to Russia (April 2022)
reportThe Record / Recorded Future News: How Ukraine's volunteer hackers have created a 'coordinated machine' around low-level attacks (April 2024), canonical Ted interview + CyberPeace Institute
reportEuromaidan Press: How Ukraine built a volunteer IT army from scratch (January 2024)
reportCEPA: Ukraine Volunteer IT Army Confronts Tech, Legal Challenges (October 2024)
reportCyberScoop: Research questions potentially dangerous implications of Ukraine's IT Army, canonical Soesanto research coverage
reportStefan Soesanto / Center for Security Studies Zurich: canonical 32-page IT Army research paper
reportMykhailo Fedorov / Ukrainian Minister of Digital Transformation: canonical Feb 26 2022 founding call + ongoing operational reporting
reportYegor Aushev: canonical defensive Ukrainian IT Corp ~1000-1500 specialists parallel
reportTed: canonical IT Army spokesperson 2023-2024 interviews
reportCyberPeace Institute Geneva: canonical 92-attack documented tracking

Operational

State sponsor

Ukrainian government partial-association, formed via direct public call by Minister of Digital Transformation Mykhailo Fedorov February 26, 2022. However, both group + Ukrainian state officials claim cooperation hasn't extended beyond initial establishment. Per CyberScoop + Ukrainian Ministry of Digital Transformation: "ministry doesn't represent [IT Army]... we are partners and have the one enemy." Group operates in legal grey area per Ted spokesperson.

Per Stefan Soesanto Center for Security Studies analysis: "the public side of the IT Army serves as a 'vessel' for volunteer distributed denial-of-service attacks on Russian government and private company websites" + "non- public attacks that show at least some coordination or cooperation with intelligence services." Attribution chain: (1) Wikipedia + CSIS canonical longstanding tracking: per CSIS Strategic Technologies Blog: "Fedorov, meanwhile, began creating an offensive IT volunteer group, officially launched as the IT Army of Ukraine on February 26. The Army organized around a Telegram channel, which, supported with calls by other Ukrainian government organizations, ballooned to 300,000 members by March 2022, including committed IT professionals, amateur volunteers, and interested observers." (2) Foreign Policy + Mykhailo Fedorov canonical February 26 2022 launch: per Foreign Policy: "on Feb. 26, Ukrainian Vice Prime Minister Mykhailo Fedorov took a step no other government official in the world likely ever has: He publicly called on volunteer hackers to take down another country's websites. And he had a list of 31 Russian government, bank, and corporation websites ready to go.

Within days, Ukraine had amassed an 'IT army' of more than 400,000 volunteers." (3) CEPA canonical 25-30 Generals + Colonels organizational structure: per CEPA: "The two largest Ukrainian hacktivist groups have pledged to scale back cyber-attacks and adhere to new rules of engagement set forth by a war watchdog. Ukrainian intelligence and defense officials are moving to take control. Operations are reportedly organized by 25-30 'Generals' from Ukrainian government agencies, coordinating high-level hackers, or 'Colonels.'" (4) CyberPeace Institute Geneva canonical 92- attack documented tracking: per The Record: "a spokesperson from the Geneva-based nonprofit CyberPeace Institute.

Its researchers detected at least 92 cyberattacks attributed to the IT Army over the past two years, the group itself claims that its attacks have impacted over 400 Russian companies in the last year alone." (5) Mykhailo Fedorov canonical Leonardo airline booking system attribution: per CEPA: "Ukraine's Minister of Digital Transformation, Mykhailo Fedorov, reported last month that the country's IT Army had orchestrated a significant DDoS attack on Russia's Leonardo airline booking system, leading to substantial disruptions at Russia's major airports. 'If Ukrainian airports cannot operate because of the war, why should Russian ones?' questioned Fedorov." (6) Stefan Soesanto Center for Security Studies Zurich 32-page paper: per CyberScoop: Soesanto wrote "that the public side of the IT Army serves as a 'vessel' for volunteer distributed denial- of-service attacks on Russian government and private company websites... the IT Army's Telegram channel has listed at least 662 Russian targets for potential DDoS attacks... while also carrying out non-public attacks that show at least some coordination or cooperation with intelligence services." Operational mission objective: Counter-Russia offensive cyber operations supporting Ukrainian war effort. Primary DDoS degradation of Russian government + state media + banking + corporate infrastructure to "make life so unpleasant and inconvenient for Russian citizens that they would question the war" per Fedorov. Strategic targeting of Russia infrastructure supporting war effort.

Non-public coordination with Ukrainian defense + intelligence services per Soesanto analysis.

Operational target profile
  • Russian government websites primary.
  • Russian state media primary.
  • Russian banking signature (Gazprombank + June 2024 "largest DDoS attack in history")
  • Russian corporate infrastructure secondary.
  • Russian airline + transit signature (Leonardo airline booking system disrupting major airports)
  • St. Petersburg International Economic Forum 2024 signature.
  • Russian energy industry secondary (10x DDoS increase year-over-year per Russian media May 2024)
  • Russian census + critical infrastructure primary The cluster fills the February-2022-onward-Ukrainian- volunteer-offensive-operations + Mykhailo-Fedorov- ministerial-call-to-arms + 300000-400000-volunteer- mobilization + DDoS-russia-government-banks-media- corporate + Leonardo-airline-booking-system-airport- disruption + June-2024-largest-ddos-attack-history- banking + 25-30-Generals-Colonels-organizational- structure + CyberPeace-Institute-92-attacks- documented + ~1B-damage-estimate position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
Motivations
ukrainian_counter_russia_offensive_cyber_operations_supporting_war_effort, russian_government_state_media_banking_critical_infrastructure_disruption, russian_public_opinion_war_questioning_objective, russian_war_economy_strategic_degradation_objective, mykhailo_fedorov_ministerial_call_to_arms_signature_organizational_founding
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)20/60 · 33%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MYKHAILO FEDOROV MINISTERIAL CALLS TO ARMS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin