← Back

AvangardSec announces Operation Bloodborne, a coordinated campaign targeting sensitive sectors in Germany and Spain

Leer en Español
Print Share

Executive Summary

AvangardSec publicly announced the launch of Operation Bloodborne, a coordinated cyber campaign targeting entities in Germany and Spain. The operation was reportedly organized by Eye of Sauron and is said to involve Pol4rity and INTEID.

The announcement identifies energy grids, financial services, logistics and companies linked to scientific activities as potential sectors of interest. It also mentions operational tools associated with the actors’ ecosystem, including DEAFTICKv3 and AVANWARE.

Key Judgments

  • Operation Bloodborne represents an attempt to formalize a coordinated campaign under a common identity, bringing together actors previously observed within the pro-Russian hacktivist ecosystem.
  • The declared selection of sectors points to infrastructure with economic, operational and reputational value for Germany and Spain.
  • The advance publication serves an information-pressure function by seeking to create expectations of hostile activity before publicly verifiable incidents emerge.
  • The announcement incorporates a geopolitical narrative intended to justify the operation within a propagandistic framework promoted by the actors.
  • The attacks have not yet been independently verified.

What Happened

AvangardSec announced the official launch of Operation Bloodborne and attributed its organization to Eye of Sauron. The publication presents Pol4rity as a joint participant and reports the addition of INTEID.

The message identifies Germany and Spain as countries of interest and lists four sectors: energy, finance, logistics and scientific companies. The wording does not identify specific organizations or provide technical evidence of compromises already carried out.

The publication also addresses SOC teams and suggests the existence of tools previously used in campaigns associated with the participating actors. The visible references include DEAFTICKv3 and AVANWARE — also referred to as Avangard Ultimate — as well as other alleged components that are not described in detail.

The announcement frames the campaign as a response to policies attributed to Germany and Spain within the broader confrontation between Russia and European countries. Part of this narrative includes allegations intended to establish the discursive positioning of the operation and the actors behind it.

Operational Assessment

At this stage, iQBlack assesses Operation Bloodborne as a publicly announced campaign rather than a sequence of confirmed incidents. The use of a specific name, the identification of participants and the enumeration of sectors suggest planning and coordination among pro-Russian actors.

The explicit mention of sensitive sectors also broadens the function of the announcement. Although there is still no evidence of technical impact, the publication seeks to generate pressure on potential victims, defensive teams and institutional audiences. The expectation of hostile activity can produce reputational and operational effects even before an intrusion is confirmed.

It is not yet possible to determine whether the campaign represents a coordinated structure with sustained capabilities. Nor can it be established that all participants possess the same technical level, degree of involvement or responsibility in potential future operations.

Intelligence Significance

The analytical value of Operation Bloodborne lies in the combination of political signaling, the construction of a collaborative identity and the advance selection of strategic sectors.

If consistent claims, verifiable technical evidence or incidents compatible with the declared objectives emerge in the coming days, the campaign could consolidate into an operational framework used to coordinate or present distributed activity against European organizations.

If the activity proves limited or predominantly performative, the announcement would remain relevant as a pressure mechanism and as an indicator of narrative alignment among pro-Russian actors.

In either scenario, Operation Bloodborne warrants dedicated monitoring because it introduces campaign indicators capable of concentrating future claims against Germany and Spain and connecting technical activity with a broader geopolitical narrative.

Analytical Closing

Operation Bloodborne formalizes a new signal of pro-Russian cyber pressure against sensitive sectors in Germany and Spain.

Pending verifiable evidence regarding victims or technical impact, iQBlack assesses the campaign as an operational declaration under monitoring through 3C-INT. Its immediate relevance does not depend solely on confirmed attacks, but also on its capacity to shape defensive expectations and project activity against infrastructure of strategic value.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved