Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
KillNet
ID: 9b3cd18f79d9e1d51728a310139561c332348
Hacktivist Group
Collective
DDoS Crew
Hacktivism
Threat types: Intrusion, Hacking, DDoS, Propaganda, Operational Disruption, Pro-palestine
Progress: 80%
Completeness: 76%
Freshness: 90%
Operation zone: —
Aliases
Limited alias preview
| KillMilk | KillNet Syndicate | Ki************** | — |
Showing 2 of 3 aliases in free preview.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium-high
KillNet is a pro-Russian hacktivist ecosystem primarily associated with coordinated DDoS waves designed to disrupt availability and amplify political messaging. Microsoft’s 2023 analysis highlights KillNet and affiliate activity targeting healthcare with multi-vector DDoS patterns including application-layer resource depletion behaviors. Reporting in 2025 indicates KillNet resurfaced after a period of reduced visibility, with analysts discussing rebranding and potential drift toward for-hire/reputation dynamics. Defenders should prioritize DDoS resilience engineering, rate limiting, multi-region failover, and incident communication readiness over malware-centric controls.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1498.001 | Direct Network Flood | TA0040 |
|
| T1498.002 | Reflection Amplification | TA0040 |
|
| T1583.006 | Web Services | TA0042 |
|
| T1598 | Phishing for Information | TA0043 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.
Showing 1–8 of 8 images
Free Preview
Propaganda
Free Preview
Avatar
Free Preview
Propaganda
Free Preview
Propaganda
Free Preview
Propaganda
Free Preview
Propaganda
Free Preview
Propaganda
Free Preview
Propaganda
Showing 4 of 8 images in preview mode. Additional evidence is restricted for Analyst and Premium plans.