Hacktivists turn to other clusters to enhance attacks

Hacktivists turn to other clusters to enhance attacks

Ideologically motivated groups increasingly cooperate with other adversaries
August 11, 2026

Insolent Hyena obtains access to victim infrastructures from other threat actors and uses it in subsequent attacks.

Hacktivists typically target organizations to generate publicity. They publish sensitive data stolen from organizations and their customers or simply claim responsibility for the attack. To gain initial access, they can either breach a victim environment themselves or acquire data from other clusters.

We have seen a growing trend of cooperation between hacktivists and adversaries driven by other motivations. By working together, they can exchange valuable intelligence about their targets. The Insolent Hyena campaign we observed between early 2026 and July clearly illustrates this trend. The attackers targeted Russian organizations across the scientific, educational, government, IT, retail, and engineering sectors. We believe that they either purchased or obtained free access to victim infrastructures from clusters with different motivations. This kind of collaboration allows otherwise unrelated adversaries to pursue shared strategic objectives.
Oleg Skulkin
Head of BI.ZONE Threat Intelligence

During the campaign, Insolent Hyena also employed the ClickFix social engineering technique to access target environments. The attackers presumably distributed phishing emails containing a link to a fake website of a regulatory authority. After redirection, victims were prompted to complete an I am not a robot CAPTCHA and press the displayed key combination. These actions triggered subsequent lateral movement.

Beyond social engineering, Insolent Hyena relied on a wide range of tools. It used the custom‑built NightWire remote access trojan to maintain covert control of compromised systems and the Excalibur stealer to exfiltrate data. The threat actor also employed the NetSupport legitimate remote access tool to disguise its activity as genuine administrative actions, the CapDoor trojan to gain persistence, and the AdaptixC2 and Cobalt Strike post‑exploitation frameworks to orchestrate and direct the intrusion.

Building an effective cybersecurity strategy requires an understanding of the methods and tools used by adversaries. Portals such as BI.ZONE Threat Intelligence provide up‑to‑date details on current threats, attackers, tactics, techniques, and tools.