Killing Killnet

Alex Holden

DEF CON 33 · Day 1 · Main Stage

Overview

In a captivating talk at DEF CON, Alex Holden, a cybersecurity veteran and founder of Hold Security, unveiled an extraordinary tale of cyber warfare and unconventional disruption. Titled "Killing Killnet," the presentation detailed a bold, multi-faceted operation to dismantle Killnet, a notorious pro-Russian hacktivist group. This wasn't a story of traditional network defense, but rather an intricate intelligence-led campaign that targeted the group's financial and operational lifelines through an unexpected vector: a major Russian dark web drug marketplace.

Watch on YouTube

Visual summary for Killing Killnet by Alex Holden
Visual summary for Killing Killnet by Alex Holden

Key moments

  1. 0:00 Introduction and speaker's history with Russian hackers
  2. 2:08 Unmasking Nikolai Serafimov, Killnet's leader
  3. 3:20 Killnet's origins and legitimizing state-sponsored hacktivism
  4. 5:30 How Killnet recruited unemployed IT personnel
  5. 7:50 Killnet calls for attacks on hospitals globally
  6. 8:50 Identifying Solaris as Killnet's critical support

Killing Killnet

Speakers: Alex Holden

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=wVY47hNzgJk

Overview

In a captivating talk at DEF CON, Alex Holden, a cybersecurity veteran and founder of Hold Security, unveiled an extraordinary tale of cyber warfare and unconventional disruption. Titled "Killing Killnet," the presentation detailed a bold, multi-faceted operation to dismantle Killnet, a notorious pro-Russian hacktivist group. This wasn't a story of traditional network defense, but rather an intricate intelligence-led campaign that targeted the group's financial and operational lifelines through an unexpected vector: a major Russian dark web drug marketplace.

Holden, whose company Hold Security has been tracking Russian threat actors for over 15 years, presented a personal and adventurous account of how a small team of nine individuals took on a formidable adversary. The talk highlighted the evolving landscape of cyber conflict, where state-sponsored hacktivism blurs the lines between cybercrime and geopolitical aggression. By strategically exploiting a hidden dependency, Holden and his team delivered a decisive blow to Killnet, showcasing the power of creative intelligence operations in modern cybersecurity.

This article delves into the intricate details of their operation, from understanding Killnet's origins and motivations to the technical exploits that brought down a significant dark web entity, ultimately leading to the disarray and eventual demise of the hacktivist collective. It serves as a testament to the impact that targeted, intelligence-driven disruption can have on even the most entrenched and state-backed cyber threats.

Background

▶ Watch: Introduction and speaker's history with Russian hackers (0:00)

The emergence of Killnet marks a significant shift in the landscape of cyber warfare and hacktivism. The group, led by Nikolai Serafimov, known by his online alias Killm, began its operations in November 2021, initially focusing on distributed denial-of-service (DDoS) attacks against various targets, including elements of the Russian government itself. However, a pivotal shift occurred a day before Russia's invasion of Ukraine in February 2022, when Killnet publicly declared its allegiance to the Russian government. From that point forward, Killnet became a prominent vehicle for Russian propaganda and rhetoric, targeting entities deemed "enemies of Russia."

What made Killnet particularly alarming was its normalization of cyber attacks as a legitimate form of warfare, openly endorsed by Russian government officials, including members of the Duma (Russia's equivalent of Congress). These officials not only encouraged citizens to engage in cyber warfare against external enemies, including the United States, but also suggested that participation in groups like Killnet was equivalent to serving in the Russian armed forces. This state endorsement legitimized hacktivism and paved the way for similar groups in other geopolitical conflicts, as observed in the Middle East and elsewhere.

Killnet's recruitment strategy also represented a novel approach. Post-invasion, many Russian citizens employed by Western companies in IT roles (developers, system administrators, cybersecurity professionals) were summarily fired. These individuals, often holding residual access or knowledge of their former employers' systems, became a pool of disaffected talent with a "vendetta to pick." Killnet successfully brought these individuals, who previously wouldn't have considered themselves cybercriminals, into their ranks. The talk even cited an anecdotal example of a grandmother joining Killnet, clicking "reload" on her old computer to contribute to DDoS attacks, illustrating the wide net cast by the group.

The group's propaganda was as aggressive as its attacks. Its official Telegram channel, which at its peak boasted over 100,000 members, featured vile content, including photoshopped images of Lockheed Martin executives in caskets, threatening those who supported Ukraine. Their attacks caused tangible disruption, affecting financial systems and airports, but their propaganda component was equally damaging. A particularly egregious example occurred in January 2023, when Killm explicitly called for attacks against hospital systems in the United States, Great Britain, Germany, and other European countries, concluding with the chilling postscript: "Kill them first. This is our enemy." This demonstrated Killnet's willingness to target the most vulnerable, solidifying its status as a truly malicious adversary.

Hold Security's small team of nine recognized the gravity of this threat. A breakthrough in their intelligence gathering came in October 2022, when Killm, in an interview with Russian state media, explicitly credited a dark web group named Solaris for crucial support, stating that "without this group... Kilnet would not be able to move forward." This statement provided the critical link: if Solaris could be neutralized, Killnet's operational capacity would be severely impaired. Hold Security's long-standing expertise in tracking dark web activities, particularly illegal drug marketplaces as a means to identify and locate cybercriminals, positioned them uniquely to exploit this connection. Solaris, a major Russian dark web forum and drug sales platform launched in 2017 by a figure known as Zanzi, operated over a thousand stores across hundreds of Russian cities, making its connection to a hacktivist group highly unusual but strategically exploitable.

Key Findings

▶ Watch: Killnet's origins and legitimizing state-sponsored hacktivism (3:20)

The central discovery that underpinned Hold Security's operation was the explicit, publicly declared dependency of the pro-Russian hacktivist group Killnet on the Solaris dark web drug marketplace. Killm, Killnet's leader, acknowledged in a state media interview that Solaris was essential for Killnet's continued operations, effectively revealing a critical vulnerability in his group's ecosystem. This finding transformed the strategic objective: instead of directly countering Killnet's DDoS attacks, the goal became to "kill" Killnet by cutting off its life support system – Solaris.

Hold Security's extensive prior intelligence on dark web operations, including Solaris, revealed that Killm himself was an ex-convict with a history in illegal drug operations in Russia, further cementing the link between the hacktivist and the illicit marketplace. The team leveraged their pre-existing, long-term access to Solaris, which had been established years prior, to initiate a campaign of disruption.

The primary results of their operation were multi-fold:

  1. Financial Disruption and Reputational Damage: Hold Security orchestrated the transfer of nearly $50,000 USD from Solaris drug dealers' funds to a Ukrainian charity, a move that was widely publicized by Forbes magazine. This not only siphoned funds from the illicit economy but also severely damaged Solaris's credibility and perceived security.
  2. Public Exposure of Solaris: The team later published a comprehensive exposé, revealing Solaris's internal architecture, its entire source code repository, database dumps, communication components, and information about its shops and Tor exit nodes. This unprecedented disclosure made Solaris's operations transparent to the world, including law enforcement and competing criminal groups.
  3. Dismantling of Solaris: Following the public exposure, Solaris was quickly subsumed by a rival dark web platform, Kraken, and its founder, Zanzi, abandoned the project. Solaris eventually faded into obscurity and ceased to exist approximately a year later.
  4. Disarray and Demise of Killnet: Crucially, the disruption of Solaris directly correlated with the decline of Killnet. Hold Security observed the Russian government withdrawing financial support for Killnet, leading to Killm's rapid financial ruin, including filing for bankruptcy and his wife taking microloans. Killnet publicly entered disarray, attempting to pivot to a for-profit model, disbanding, briefly reforming under different leadership (which turned out to be Killm himself), and even calling for peace. Despite a brief resurgence following the October 7th, 2023 Hamas attack, Killnet's influence dwindled. By 2024, its Telegram channel, once boasting 100,000 followers, was sold for a mere $10,000 USD to a group called the Anan Club, which ironically began fighting Russian illegal drug trade within the channel. Killm himself was doxxed by Russian media and faded from prominence.

These findings demonstrate that targeting an adversary's hidden dependencies and financial infrastructure, even through unconventional means, can be a highly effective strategy for disruption, leading to the collapse of seemingly robust cyber threat groups.

Technical Deep Dive

▶ Watch: How Killnet recruited unemployed IT personnel (5:30)

Hold Security's technical approach to disrupting Solaris, and by extension Killnet, was rooted in a combination of long-term intelligence gathering, opportunistic access, and strategic escalation. The initial foothold into Solaris was gained serendipitously years before the Killnet operation. Around 2017-2018, Zanzi, Solaris's founder, approached one of Hold Security's "outer egos" on the dark web, seeking assistance with a PHP code issue on one of his servers. This provided the critical entry point.

During this "consultation," Zanzi granted Hold Security root access to a Solaris server. Leveraging this trust, Hold Security requested permission to install a "fail-safe switch" to prevent being locked out in case of future issues. This was a pretext to install a persistent backdoor on the system. As Alex Holden metaphorically put it, "we were invited inside... we were given the backdoor." This backdoor provided Hold Security with years of covert monitoring capabilities over Solaris's operations.

Solaris itself was a remarkably complex ecosystem designed for illicit drug trade within Russia. Its architecture facilitated transactions where users could convert traditional bank account funds (via credit or debit cards) into Bitcoin, which was illegal in Russia at the time, to then purchase drugs. The platform managed a sophisticated network involving drug buyers, sellers, runners, dealers, and shop operators. It featured automated components, monitoring systems, a comprehensive store catalog, and even its own anti-DDoS systems, ironically a capability that likely benefited Killnet.

Despite having only initial access to one or two servers, Hold Security employed a multi-pronged strategy to escalate their control and deepen their understanding of Solaris's infrastructure:

  1. SSH Session Keys: The administrators of Solaris, like many developers, relied heavily on SSH authorization keys for secure access. Hold Security was able to obtain and leverage these keys to log into additional servers within the Solaris network.
  2. Ansible Automation: For servers that couldn't be accessed directly via SSH keys, Hold Security exploited the presence of Ansible, an open-source automation engine. By gaining control over Ansible components, they could execute scripts and commands remotely to gain access to further systems.
  3. Zabbix Monitoring: For any remaining inaccessible servers, Hold Security utilized Zabbix, a popular enterprise-class open source monitoring solution. Since these servers had to be monitored, they likely ran agents or exposed interfaces that could be exploited. Hold Security used login scripts within Zabbix to gain control over these systems, effectively achieving pervasive access across Solaris's infrastructure.

This systematic escalation allowed Hold Security to "take quite a bit of control over the Solaris system." The first overt action, demonstrating their deep access, was the manipulation of fund transfers. They enabled drug dealers to inadvertently push buttons that redirected funds from their illicit transactions to a Ukrainian charity supporting the elderly and sick during wartime. This resulted in nearly $50,000 USD being transferred, a story later covered by Forbes magazine, which also highlighted the connection between Solaris and Killnet.

Following this initial strike, Solaris administrators, after a week of "maintenance," claimed to have fixed all vulnerabilities. Hold Security then re-entered the system, specifically targeting the GitLab server, which housed Solaris's version control and source code. Their analysis of the changes revealed superficial "fixes": the onion address of a server was changed, the logo and copyright were updated, and the Bitcoin address for transactions was altered. These cosmetic changes indicated a failure to address the underlying security breaches.

Three weeks after the Forbes story, Hold Security launched their decisive technical strike. They published a comprehensive disclosure on their own site, explicitly detailing the connection between Russian illegal drug trade and Killnet. This disclosure included:

  • Components related to Solaris's Tor nodes monitoring.
  • Their entire source code repository.
  • Multiple database dumps.
  • Internal communication components.
  • Details of various Solaris shops.

This public release of highly sensitive internal data was the ultimate technical blow, rendering Solaris's operations transparent and effectively destroying its trustworthiness and operational security. This move directly contributed to its rapid demise, as customers and rival groups, such as Kraken, could now exploit its exposed infrastructure.

Demo / Proof of Concept

▶ Watch: Killnet calls for attacks on hospitals globally (7:50)

While the talk did not feature a live, real-time technical demonstration in the traditional sense, the entire operation against Solaris and Killnet served as a real-world, high-stakes proof of concept for unconventional cyber disruption. The "demo" was the tangible impact of their actions, meticulously documented and presented.

The first significant demonstration of Hold Security's deep access and control within the Solaris network was the orchestrated transfer of funds. By leveraging their access, they created a scenario where Solaris drug dealers, through their regular operational processes, inadvertently redirected nearly $50,000 USD from their illicit earnings to a legitimate Ukrainian war charity. This act, later reported by Forbes magazine, was a powerful proof of concept, showing that Hold Security could not only penetrate the system but also manipulate its core financial functions for ethical purposes. It demonstrated a level of control that went beyond mere observation, directly impacting the adversary's finances and reputation.

The second and more comprehensive proof of concept was the public release of Solaris's internal infrastructure and intellectual property. After Solaris's administrators claimed to have patched their systems, Hold Security accessed their GitLab server to verify the "fixes." Finding only superficial changes, they proceeded to publish a wealth of highly sensitive information. This included the entire source code repository for Solaris, various database dumps, internal communication components, details about their Tor exit nodes and monitoring systems, and information about their numerous illegal shops. This public disclosure was the ultimate demonstration of their compromise, proving unequivocally that Solaris's security was fundamentally broken and that Hold Security possessed full insight into its operations.

These actions were not mere theoretical exercises; they were real-world interventions with immediate and far-reaching consequences. The public exposure and financial disruption directly led to Solaris's rapid decline and eventual collapse, which in turn triggered a cascade of negative effects on Killnet, thereby validating the efficacy of Hold Security's strategic and technical approach.

Defensive Implications

▶ Watch: Identifying Solaris as Killnet's critical support (8:50)

The "Killing Killnet" operation offers profound defensive implications, particularly in the realm of strategic intelligence and non-traditional threat mitigation. For defenders, the key takeaway is to broaden the scope of threat intelligence beyond traditional network perimeter defense and malware analysis.

  1. Understand Adversary Ecosystems and Dependencies: Defenders must recognize that sophisticated threat actors, whether state-sponsored hacktivists or cybercriminals, rarely operate in isolation. They often rely on a complex ecosystem of financial, logistical, and technical support systems. Identifying these non-obvious dependencies – such as the link between Killnet and Solaris – can reveal critical vulnerabilities for disruption. This requires intelligence gathering that extends into dark web forums, illicit marketplaces, and even geopolitical analysis.
  2. Embrace Unconventional Disruption Tactics: Traditional defensive measures like firewalls, EDR, and patching are essential but insufficient against highly motivated and state-backed adversaries. This case highlights the effectiveness of "active defense" or "disruption-as-a-service" strategies that aim to dismantle the adversary's capabilities rather than merely blocking their attacks. Defenders should explore legal and ethical frameworks for engaging in such activities, or support entities that do.
  3. Blurring Lines of Threat Actors: The Killnet story underscores the increasing convergence of cybercrime, hacktivism, and state-sponsored activity. Russian government endorsement of Killnet, coupled with its recruitment of unemployed IT professionals, blurs the traditional categorization of threats. This means intelligence analysts need to track individuals and groups across these categories, as their allegiances and methods can shift rapidly.
  4. Intelligence on Illicit Financial Flows: The success of targeting Solaris's financial mechanisms demonstrates the power of following the money. Understanding how threat actors finance their operations, whether through cryptocurrency, dark web marketplaces, or other means, provides critical leverage points. Defenders, in collaboration with law enforcement, should invest in capabilities to trace and disrupt these financial networks.
  5. The Power of Public Exposure: Strategic public disclosure of an adversary's vulnerabilities, internal data, or illicit connections can be a potent defensive tool. It damages reputation, erodes trust among members, attracts law enforcement scrutiny, and can even incite rival criminal groups. Organizations should consider how controlled, ethical disclosure could be integrated into a broader defensive strategy.
  6. Internal Threat Mitigation for Disaffected Employees: The recruitment of unemployed Russian IT professionals by Killnet highlights a potential internal threat vector. Companies operating in politically volatile regions should be acutely aware of the risks posed by mass layoffs or politically motivated dismissals, as these individuals might become vectors for insider threats or join adversarial groups. Implementing robust offboarding procedures and continuous monitoring for former employee access are crucial.

Ultimately, the "Killing Killnet" operation advocates for a proactive, intelligence-led defensive posture that seeks to understand, map, and disrupt the entire operational fabric of an adversary, rather than solely reacting to their direct attacks.

Key Takeaways

  • Unconventional Disruption is Effective: Directly targeting an adversary's hidden operational and financial dependencies, rather than just their cyberattacks, can lead to their complete dismantling.
  • Adversary Ecosystem Mapping is Crucial: Understanding the broader network of support, funding, and alliances (e.g., Killnet's link to Solaris) provides critical leverage points for strategic disruption.
  • Blurring Lines of Cyber Conflict: The Killnet case exemplifies the increasing convergence of state-sponsored hacktivism, cybercrime, and geopolitical warfare, demanding a more holistic approach to threat intelligence.
  • Dark Web Intelligence is a Force Multiplier: Expertise in monitoring and infiltrating dark web marketplaces can yield invaluable intelligence on threat actor identities, locations, and operational vulnerabilities.
  • Reputational and Financial Attacks are Potent: Disrupting an adversary's financial flows and publicly exposing their illicit operations can severely damage their credibility, membership, and ability to operate.
  • Small, Agile Teams Can Make a Difference: A dedicated, intelligence-driven team, even a small one, can achieve significant impact against large, state-backed cyber threats.

About the Speaker(s)

Alex Holden is a highly experienced cybersecurity professional and the founder of Hold Security. Born in Kyiv, Ukraine, he later became a refugee from the former Soviet Union, settling in Milwaukee, Wisconsin, where he has spent his adult and professional life. Holden boasts a career spanning his entire adult life in cybersecurity, with the last 15 years specifically dedicated to tracking down malicious actors and understanding their evolving tactics. He is known for his tenacious pursuit of cybercriminals and has made significant contributions to the field, including being on the front page of The New York Times in 2014 for uncovering one of the biggest breaches perpetrated by Russian hackers, an act he proudly states made Vladimir Putin "mad." His work reflects a deep personal commitment to combating cyber threats, particularly those originating from Russia.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Holden presents a genuinely novel intelligence operation with real-world consequences — not a framework, not a product pitch, not a retrospective sanitized for LinkedIn. The chain from a PHP help request to persistent backdoor to charity redirect to full source dump is specific, documented, and actually happened. Minor gap is that the technical escalation chain (SSH keys → Ansible → Zabbix) is described but not demonstrated at a level that lets a practitioner reproduce the methodology.

Heather Calloway (CISO) — SOLID

A genuinely compelling intelligence operation story with real-world consequences — Killnet is down, Solaris is gone, and the causal chain holds. But this is operator folklore more than a transferable playbook, and the talk never seriously confronts the legal, ethical, or governance dimensions of a private company running offensive disruption operations against foreign criminal infrastructure.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33