Solntsepek
- First seen
- 2017-06-27 00:00:00
- Origin
- RU
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:11:15
Targeted industries: technology-and-telecommunications government-and-public-sector energy-and-utilities
Targeted regions: country_code:ua
Context
Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobile operator, and have been linked to previous attacks on Ukrainian infrastructure. Solntsepek has been associated with the Sandworm hacking group, known for their destructive cyberattacks, including the NotPetya worm. They have also engaged in hostile activities, such as revealing personal details of Ukrainian soldiers.
Reports & references
- kyivindependent.com — Sbu Russian Hacker Group Reponsible For Kyiv Star Cyberattack (report)
- dev.ua — Atakovali Suspilne Provaiderov I Minrazvitiya Obschin Kto Stoit Za Rossiiskoi Gruppirovkoi Solntsepek Kotoraya Aktivizirovala Napadeniya Na Ukrainskie Struktury (report)