APT / THREAT GROUP HACKTIVISM

Zarya

🇷🇺Russia-attributed
1
campaigns
2
aliases
Last seen:Mar 17, 2026

Intelligence Profile

Zarya is a pro-Russian hacktivist group that emerged in March 2022. Initially operating as a special forces unit under the command of Killnet, Zarya has since become an independent entity. The group is primarily known for engaging in Denial-of-Service attacks, website defacement campaigns, and data leaks. Zarya targets government agencies, service providers, critical infrastructure, and civil service employees, both domestically and internationally.

Threat Analysis

Zarya is a known-sophistication threat actor attributed to Russia, engaged in cyber operations with a primary motivation of hacktivism.

As a hacktivist-aligned entity, Zarya conducts operations driven by ideological, political, or social grievances, typically through website defacements, DDoS attacks, and the leaking of sensitive data to advance a public narrative.

Known Campaigns

Zarya — Active Operations March 2026

Zarya is a hacktivism threat actor attributed to Russia. Zarya is a pro-Russian hacktivist group that emerged in March 2022. Initially operating as a special forces unit under the command of Killnet, Zarya has since become an independent entity. The group is primarily known for engaging in Denial-of-Service attacks, website defacement ...

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Motivation hacktivism
Origin🇷🇺 Russia
Aliases2
SourceMalpedia

Also Known As

UAC-0109Zarya

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.
Zarya — APT / Threat Group | Threat Intelligence | CTIWATCH.COM