Eye Of Sauron
Eye Of Sauron is a Telegram-centric pro‑Russia hacktivist brand that appears in OSINT primarily through claims and repost-driven narratives. The most prominent set of claims ties the group (often alongside PalachPro) to the alleged compromise and/or disruption of “Sonata” / “Sonata Messenger,” described in reporting as a messaging system used by Ukrainian military personnel.
A Telegram indexing archive (Telemetr) for the channel “EYE OF SAURON” includes posts framing the activity as a targeted operation and asserting access to an active account of the service, which the group uses to dispute claims that the platform is secure. Additional reporting (often citing Russian Telegram sources) repeats the same narrative and extends it to other claimed targets, including Ukrainian port-related infrastructure.
Because much of the publicly visible record is claim-driven and relies on secondary reporting, confidence is highest in the actor’s existence and propaganda/claim posture, and lower regarding the true operational impact (service-level disruption vs. confirmed system compromise). This profile treats the Sonata narrative as an intent and targeting indicator and emphasizes defender controls aligned to high-probability tactics: exposed service abuse, credential compromise, and disruption operations in campaign windows.
Confidence is high that Eye Of Sauron is an active Telegram brand producing operation claims. Confidence is low–medium that the Sonata incident produced the full operational effects described in secondary reporting (telemetry not available in reviewed sources).
ATT&CK
MITRE ATT&CK
Research