Solntsepek

First seen
2017-06-27 00:00:00
Origin
RU
Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:11:15

Targeted industries: technology-and-telecommunications government-and-public-sector energy-and-utilities

Targeted regions: country_code:ua

Context

Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobile operator, and have been linked to previous attacks on Ukrainian infrastructure. Solntsepek has been associated with the Sandworm hacking group, known for their destructive cyberattacks, including the NotPetya worm. They have also engaged in hostile activities, such as revealing personal details of Ukrainian soldiers.

Reports & references

  • kyivindependent.com — Sbu Russian Hacker Group Reponsible For Kyiv Star Cyberattack (report)
  • dev.ua — Atakovali Suspilne Provaiderov I Minrazvitiya Obschin Kto Stoit Za Rossiiskoi Gruppirovkoi Solntsepek Kotoraya Aktivizirovala Napadeniya Na Ukrainskie Struktury (report)

External references