Grupo hacktivista

62IX Group

62IX Group is assessed as an active or resurgent pro-Russian hacktivist collective whose best-supported operational activity is distributed denial of service. Public infrastructure centers on the Telegram channel @[redacted], a reserve channel, a forum, an advertised “botnet” project and the founder alias @[redacted]. The group’s civil identity, physical location, membership size and command structure remain unknown.

Independent reporting places 62IX within the wider pro-Russian DDoS ecosystem. Radware counted 168 unique DDoS claims attributed to 62IX during 2024, while NETSCOUT observed a wider Romanian DDoS surge in June 2024 and included 62IX among groups claiming participation. These findings support repeated DDoS activity, but neither source proves that every actor post produced sustained target impact.

The group blends ideological messaging, coalition participation and commercial promotion. Recruitment posts sought DDoS and penetration-testing roles; later messaging promoted paid training. A 2025 joint narrative with HKVD advertised alleged stealer products and infrastructure-hacking courses while offering no technical evidence for the claimed compromises. This crossover suggests that visibility and monetization are part of the operating model.

On 24 August 2026, 62IX amplified “Operation Desna,” presenting specifications and procurement details for a Leopard 1A5 driver simulator as obtained documents. The core details—including procurement identifier, price, supplier, address and technical scope—were already present in a public Ukrainian tender announced on 6 May 2026. The most defensible assessment is therefore public-data repackaging for influence amplification, not a confirmed intrusion. INFERENCE (confidence: high): 62IX’s current risk is driven more by availability disruption and narrative effects than by demonstrated persistent access.

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-25

ATT&CK

MITRE ATT&CK

T1498Network Denial of Service