KillNet
KillNet emerged in open reporting as a pro‑Russian hacktivist collective that leveraged distributed denial‑of‑service (DDoS) attacks as its primary operational tool. Early profiles described the group as evolving from a DDoS-for-hire orientation into more overtly political activity following Russia’s full-scale invasion of Ukraine in 2022. Microsoft’s 2023 analysis highlighted KillNet-linked campaigns targeting healthcare organizations with multi-vector DDoS patterns, emphasizing that the throughput levels were often moderate but still sufficient to disrupt unprotected web applications. In 2025, reporting indicated KillNet resurfaced after a period of reduced visibility, with analysts suggesting branding continuity while operational motives increasingly resembled reputation-and-revenue dynamics. ENISA’s Threat Landscape 2025 notes the claimed reappearance of “Killmilk” in May 2025 within broader hacktivist ecosystem turbulence driven by platform takedowns and migration.
ATT&CK
MITRE ATT&CK
Research