Cybersecurity & Tech Foreign Relations & International Law

The Cyber Corps: Ukraine’s Least Understood Cyber Actor

Stefan Soesanto
Thursday, October 8, 2026, 2:00 PM
From overlapping operations to the IT Army’s internal split, new clues shed light on the Cyber Corps’ ties to the GUR.
Ukrainian flag in Kyiv. (Rawpixel, https://www.rawpixel.com/image/6918379; Public Domain).

By the summer of 2024, the Ukrainian military intelligence service (GUR) was one of the closest-watched actors in the Russia-Ukraine war. News outlets reported extensively about the service’s maritime drone campaign against Russia’s Black Sea fleet and drone strikes against Moscow’s strategic early-warning radar network. At the same time, the GUR had begun to self-attribute its offensive cyber operations, an unusual departure from the traditional secrecy of other intelligence services. Yet, on July 1, 2024, another development connected to the GUR passed almost unnoticed. A small band of hacktivists calling themselves the Cyber Corps (Кіберкорпус) quietly appeared on Telegram, claiming the group “was created by officers of the GUR of the Ministry of Defense.”

Whether the Cyber Corps is genuinely affiliated with the Ukrainian military intelligence service cannot be answered definitively. But a series of indicators and circumstantial evidence suggest some form of organizational relationship. To date, the GUR has neither endorsed the Cyber Corps’ claim that GUR officers created it, nor repudiated the corps’ claims taking credit for cyber operations the GUR officially conducted. Curiously, the Cyber Corps’ distributed denial-of-service (DDoS) activities also increasingly overlapped with, and ultimately led to the absorption of, parts of the IT Army of Ukraine.

The GUR Connection

The story of the Cyber Corps begins on July 14, 2024, when the group announced on Telegram that it had successfully breached the servers of Timur Ivanov, then Russia’s deputy minister of defense. According to the post, the breach accessed the ministry’s electronic document management system, which allowed the hackers to exfiltrate access certificates, organizational data, and other restricted files. The group also claimed that it used DDoS attacks as a diversion to conduct follow-on operations against the ministry, which resulted in the theft of “gigabytes of secret information.”

To support its claims of the two successful operations, the Cyber Corps published two documents and two screenshots showing structured data and records extracted from the ministry. Each screenshot was overlaid with a branded GUR watermark. Notably, the GUR used the same watermark six months earlier, when the official GUR website published screenshots from the service’s self-attributed cyber operation against servers of the Special Communications Service of the Russian Ministry of Defense.

On July 17, 2024, the Cyber Corps claimed responsibility for a DDoS attack against “enemy servers used to install software and control DJI drones for combat operations.” While the Cyber Corps did not explicitly identify its victim, the operation corresponds to the same DDoS attack that the GUR and the IT Army of Ukraine publicly disclosed five months earlier.

On Feb. 8, 2024, the official GUR website announced that its cyber specialists caused a “massive failure” in software Russian forces use to configure DJI drones for combat operations. On the same day, the IT Army of Ukraine similarly explained that it participated in a DDoS attack against “the enemy’s DJI controllers firmware update servers which are widely used at the front [...] this led to significant malfunction and delays in deploying new drones.” Analysis of the accompanying screenshots identified the affected target as the COS Project, a Russian open-source drone software community whose SOLAR software is being used “[by] units of the Russian Ministry of Defense.”

The Cyber Corps’ July 2024 post provided further details about the operation, including screenshots of what appears to be the COS Project’s customer database, which lists customer names, telephone numbers, email addresses, and procurement records for enterprise DJI drone platforms. Interestingly, the Cyber Corps also published the same screenshot testing the target’s global network accessibility that accompanied the GUR’s February 2024 announcement, although in a less cropped form.

On July 18, 2024, the Cyber Corps claimed responsibility for yet another GUR operation: the February 2024 DDoS attack against the Special Communications Service of the Russian Ministry of Defense.

Attribution by the Ukrainian Media

Between September and November 2024, the pattern expanded, with the Cyber Corps claiming responsibility for several DDoS campaigns that Ukrainian media outlets had attributed to the GUR through anonymous sources within the intelligence service.

In one instance, on Sept. 4, 2024, the Cyber Corps claimed responsibility for a 72-hour DDoS campaign in early May 2024 against the Russian telecommunications provider Tattelecom that disrupted internet connectivity within the Alabuga Special Economic Zone in Tatarstan. Notably, four months earlier, Ukraine’s public broadcaster Suspilne reported, citing “sources within the security services,” that the GUR had carried out a large-scale cyberattack against internet service providers and mobile network operators in Tatarstan.

The same pattern repeated over the following two months. On Sept. 23, 2024, the Cyber Corps claimed responsibility for a DDoS campaign against Moscow Credit Bank and Rosselkhozbank. Kyiv Post reported on the same day that “specialists from Ukraine’s Main Intelligence Directorate carried out a cyberattack” that disrupted both banks. Citing a source within the GUR, the article further quoted the official as saying that “these actions have no set end date. The Russian financial system will continue to face disruptions until the last occupier leaves Ukraine.” On the following day, the Cyber Corps claimed responsibility for a DDoS campaign that disrupted Russia’s Faster Payments System (SBP). Ukrainska Pravda subsequently reported that, according to “a source at the Main Intelligence Directorate [GUR cyber specialists] crippled the Russian national payment system SBP.”

Similarly, on Oct. 18, 2024, the Cyber Corps claimed a DDoS campaign against the Russian satellite communications operator Morsvyazsputnik. That same day, Ukrainian news outlet Babel reported that “specialists from the Main Intelligence Directorate carried out an attack on satellite communications in Russia,” adding that “sources within Ukrainian intelligence” confirmed the operation targeted Morsvyazsputnik’s information technology infrastructure.

The self-attribution pattern is quite distinct because neither the official GUR website nor its Telegram channel acknowledged any of these operations.

The Most Direct GUR Link

On July 26, 2025, the Cyber Corps announced that it launched a multilayered operation against government services and telecommunications infrastructure in the occupied territory of Crimea. According to the group, the operation combined sustained DDoS attacks with an intrusion into the Crimean Ministry of Health’s internal systems. The group subsequently published multiple screenshots, videos, and a 1.3-gigabyte archive of exfiltrated documents.

Four days later, the official GUR website announced that “as part of a large-scale cyber operation, DIU specialists accessed the servers of the so-called ‘government of Crimea.’” According to the GUR, the compromised systems contained documents about the forced deportation of Ukrainian children from the occupied regions. The announcement included four screenshots and quoted GUR spokesperson Andriy Yusov stating that “thousands of files containing crucial evidence of one of Russia’s largest war crimes—the abduction of Ukrainian children—have already been handed over to law enforcement.”

Following the GUR’s announcement, the Cyber Corps claimed responsibility for the operation and, for the first time ever, reposted an official GUR Telegram post. The group also republished the four screenshots released by the GUR as well as several other screenshots of media articles about the operation. Two months later, on Sept. 28, 2025, the Cyber Corps claimed to have intercepted additional data, including the names of deported minors and documents that describe the administrative process used to transfer children from the occupied territories. To support its claim, the group published a screenshot of a list of minors who were allegedly transferred from the Donbas region to various municipal kindergartens in the Crimean city of Alushta between 2022 and 2025. The document appears genuine and may be the only exfiltrated file from the operation to have been publicly released.

Although this episode still fell short of proving a direct organizational relationship, the chronology and their shared focus on Crimea represented the strongest observable connection between the Cyber Corps and the GUR at the time.

On Aug. 15, as this article was being written, the GUR publicly acknowledged the Cyber Corps for the first time. The official GUR website reported that “on August 10–11, 2026, […] members of the Cyber Corps community attacked the digital infrastructure of the company ‘Wildberries’ […]. The cyber operation amplified the effect of the Defense Forces’ kinetic attacks on Wildberries’ warehouses […].” The Cyber Corps subsequently used the GUR’s acknowledgment in its efforts to recruit DDoS volunteers, writing that “the official channel of the GUR of the Ministry of Defense of Ukraine confirmed the success of our joint operation […]. We are noticed, we are proud, the enemy is afraid of us. […] Join the Cyber Corps if you’re still not with us.”

Attribution by the IT Army of Ukraine

The Cyber Corps’ interactions with the IT Army of Ukraine provide another piece to the puzzle.

Over the past two years, the IT Army of Ukraine focused heavily on conducting DDoS attacks against Russian internet service providers and banks. The Cyber Corps’ emergence in the same targeting space produced two curious subsequent overlaps.

On July 24, 2024, the Cyber Corps announced a DDoS campaign against Alfa-Bank, VTB Bank, Raiffeisenbank, Rosbank, and Rosselkhozbank. Three days later, the IT Army posted on Telegram that “we are joining the GUR attack on the banks. Post Bank and Zenit Bank are almost completely non-functional, with neither client banking, POS terminals, nor cards working.”

The second overlap occurred in September 2024 when the Cyber Corps conducted a DDoS campaign against several internet service providers in Moscow and St. Petersburg. In four Telegram posts stretching from Sept. 7 to 11, the group reported it took down Smile, Rostelecom, CityLink, Lifelink, Gelicon, and Nevalink. On Sept. 10, the IT Army announced that “together with the Main Intelligence Directorate (GUR), we managed to take down as many as six (!) major internet providers in Moscow and St. Petersburg for several days,” specifically naming Smile, Rostelecom, CityLink, Lifelink, Gelicon, and Nevalink.

These two overlaps are striking because the IT Army itself acknowledged it was supporting the GUR. Yet neither the official GUR website nor the service’s Telegram channel ever mentioned these operations. But this was only the beginning of a broader convergence between the IT Army and Cyber Corps.

Absorbing Parts of the IT Army of Ukraine

The migration of prominent IT Army members to the Cyber Corps provides another possible sign of the group’s relationship with the GUR. Beginning in spring 2026, a dispute within the IT Army prompted several major DDoS contributors and tool developers to move to the Cyber Corps. The circumstances surrounding this split are particularly relevant because IT Army administrators subsequently alleged that the departing group had recruited volunteers while posing as intelligence agencies.

On June 26, the Cyber Corps launched its official website, describing itself as a “volunteer organization of engineers, analysts, and cybersecurity researchers.”

The website also introduced CyberOwl, a DDoS tool developed by OleksandrBlack, a longtime IT Army contributor who had previously developed and maintained several of the group’s tools. Notably, in April 2023, OleksandrBlack publicly revealed his identity in an interview with the BBC. CyberOwl is based on an older version of the IT Army’s DDoS Toolkit, which similarly allows users to track their own DDoS traffic and compete on the Cyber Corps website leaderboard.

The Cyber Corps leaderboard provides evidence of a broader user migration. By July, the Cyber Corps’ top three DDoS contributors were John11, littlest_giant, and Badger&Beaver. All three previously ranked among the IT Army’s top DDoS contributors. On May 24, one top 10 IT Army contributor even changed his username to “Abandon ITUA, join https://t.me/kiberkorpus.” The departures coincide with a marked decline in the IT Army’s overall DDoS traffic generation. The IT Army subsequently shut down the leaderboard on its website and has since refrained from publishing the DDoS volume its top 10 contributors are generating.

An internal crisis within the IT Army in April 2026 caused the user migration to the Cyber Corps. It is unclear what happened in late April as the IT Army administrators deleted most of the relevant Telegram messages. The remaining evidence points to a major disagreement between the group’s tool developers. In one now-deleted announcement, an IT Army administrator stated that “over the past few days, we have been forced to investigate a possible compromise of part of our infrastructure. At this time, we still have serious concerns regarding the security and transparency of our current operating environment. Therefore, we ask you to temporarily stop your devices and servers until a separate announcement from us.”

As part of the investigation, several developers demanded a full audit of the IT Army’s tooling and infrastructure. This demand was initially rejected due to concerns that such an audit might expose sensitive information and user data that could potentially lead to arrests by Ukrainian law enforcement. The dispute escalated when one administrator began banning people from the Telegram channel. On April 25, the official IT Army administrator account acknowledged that “the cause of the crisis was the refusal to allow even a minimal audit of the targets, after which the community was placed on pause. The community’s operations have now resumed after uninterrupted access for the audit was obtained.” The statement suggests that some aspect of the IT Army’s centrally managed DDoS target update mechanism was potentially interfered with.

Three days later, the IT Army proposed developing a new open-source tool that would allow transparent auditing. On May 11, OleksandrBlack released his CyberOwl DDoS tool, and two weeks later, the IT Army published its new community-developed DDoS framework, known as the BaseTool.

A longer post by the official IT Army administrator dated May 25 sheds more light on a possible GUR connection. According to the account, the dispute began over the discovery of several targets in their DDoS list whose strategic objective was either unclear or potentially unlawful, prompting the internal team to demand a full audit of the target designation pipeline. When access was eventually granted, the group around OleksandrBlack “took away all the tools, paralyzed our work here, and recruited volunteers from here while posing as intelligence agencies.” The post went on to question what kind of Ukrainian intelligence agency would be interested in shutting down the work of the IT Army—which then-Minister of Defense Mykhailo Fedorov created—and why the group in question was not officially recognized by any of the intelligence services. The post also raised concerns that IT Army volunteers could face criminal charges elsewhere in Europe if they unknowingly participate in DDoS attacks against unlawful targets.

As of this writing, the Cyber Corps’ GitHub account hosts both CyberOwl and the source code for the group’s website. One repository file is named Claude.md—a project instruction file intended for Anthropic’s Claude coding assistant. While the file provides some insights into the Cyber Corps’ website architecture and maintenance, it also states that the site is a “static volunteer community website supporting GUR MO Ukraine, hosted on GitHub Pages.”

Alternative Explanations and Conclusion

If we assume the Cyber Corps maintains no relationship with the GUR whatsoever, several aspects of the group’s behavior become difficult to explain.

A hacktivist group that falsely claims to be affiliated with Ukraine’s military intelligence service would likely seek to claim credit for as many GUR operations as possible. The Cyber Corps, however, has been remarkably selective in claiming responsibility for GUR intrusions and DDoS campaigns that align with its own operational profile, while ignoring several high-profile operations officially acknowledged by the service.

This selectivity is particularly noteworthy when it comes to the activities of the Black Owl Team (BO Team), which maintains the clearest operational relationship to the GUR and likely functions as the GUR’s premier destructive cyber unit. Yet, throughout the past two years, the Cyber Corps never attempted to claim responsibility for any of the BO Team’s operations. For example, the Cyber Corps did not associate itself with the high-profile destructive operation against the Russian drone manufacturer Gaskar in July 2025, which the BO Team, the Ukrainian Cyber Alliance, and the GUR executed. Conversely, Ukrainian media outlets have incorrectly attributed BO Team operations to the Cyber Corps several times, even though the Cyber Corps itself never claimed responsibility for these operations and never took credit in their Telegram channel.

The Cyber Corps’ relationship with the IT Army presents another conundrum. Following the IT Army’s crisis in April, several prominent members migrated to the Cyber Corps. The IT Army’s own administrator publicly alleged that individuals had taken control of parts of the organization’s infrastructure while “posing as intelligence agencies”—likely the GUR—which prompted several IT Army members to question who ultimately exercised authority over the IT Army and whether Mykhailo Fedorov could protect them should they ever face criminal prosecution within Ukraine.

One possible explanation for the GUR’s involvement in the IT Army is that the service recruited IT Army members to insert internet protocols occasionally into the group’s DDoS targeting list to secretly take advantage of the IT Army’s DDoS firepower. This might also explain why the Cyber Corps occupied the same targeting niche and eventually absorbed numerous IT Army members after the group started to investigate a possible infrastructure compromise.

Taken individually, each observation laid out in this article is open to plausible alternative explanations. Collectively, however, the evidence paints a different picture. The Cyber Corps consistently claimed a defined subset of GUR-linked cyber operations, published operational details that extended beyond official GUR information releases, repeatedly overlapped operationally with the GUR and the IT Army, was linked to GUR operations in multiple Ukrainian media reports citing intelligence sources, and ultimately absorbed experienced IT Army members.

The GUR’s official acknowledgment in mid-August 2026 of the Cyber Corps’ successful DDoS campaign against Wildberries marked a distinct change in the GUR’s public posture and provided the clearest evidence of a much tighter relationship between the GUR and the Cyber Corps. Whatever the GUR’s intentions may have been, the announcement effectively amounts to the GUR taking sides in the dispute between the IT Army and the Cyber Corps. Notably, over the past four and a half years, the GUR has never publicly acknowledged any of the IT Army’s countless DDoS campaigns despite the group’s repeated claims of having supported GUR operations.

Perhaps the most important unresolved questions lie beyond the Cyber Corps itself. Did the GUR decide that an entity it controls should replace the IT Army? Or did individuals invoke the GUR’s name to wreak havoc within the IT Army without any subsequent government repercussions? And how reliable are Ukrainian media reports that attribute cyber operations based on anonymous intelligence sources? While these questions remain unanswered, the continuing evolution of the Cyber Corps and the IT Army suggests that the story of DDoS volunteers in armed conflict is far from over.


Stefan Soesanto is a lecturer in the Department of Computer Science and Information Technology at the Lucerne University of Applied Science and Arts.
}

Subscribe to Lawfare