Versus Killnet

Alex Holden

BSidesSF 2025 — Here Be Dragons · Day 1 · Main

Overview

Alex Holden of Hold Security delivered a gripping first-person account of how his firm infiltrated and dismantled the Russian hacktivist group Killnet by targeting its financial backer — a Moscow-based illegal drug cartel. The operation exposed Killnet's leadership, redirected the cartel's cryptocurrency revenues to Ukrainian humanitarian charities, and accelerated the group's internal collapse. The story is a masterclass in finding asymmetric leverage against a massive adversary. ---

Watch on YouTube

Visual summary for Versus Killnet by Alex Holden
Visual summary for Versus Killnet by Alex Holden

Key moments

  1. 4:15 Surprising origin: Killnet initially targeted Russian government institutions
  2. 5:59 Root cause: Unemployed Russian IT workers weaponize unique skills
  3. 8:45 Key insight: Russian government exempts hacktivists from military draft
  4. 9:14 Key stat: Killnet reached 120,000 members at its peak
  5. 9:59 Case study: Killnet orchestrates targeted DDoS against US hospitals
  6. 11:00 Attack technique: Intimidating defense contractors with photoshopped casket images
  7. 11:45 Key finding: Identifying Killnet leader Killmilk as Nikolay Serafimov

Versus Killnet: How a Small Ukrainian Team Took Down Russia's Largest Hacktivist Collective

Speaker: Alex Holden

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch the full talk

Reading time: ~7 minutes

TL;DR

Alex Holden of Hold Security delivered a gripping first-person account of how his firm infiltrated and dismantled the Russian hacktivist group Killnet by targeting its financial backer — a Moscow-based illegal drug cartel. The operation exposed Killnet's leadership, redirected the cartel's cryptocurrency revenues to Ukrainian humanitarian charities, and accelerated the group's internal collapse. The story is a masterclass in finding asymmetric leverage against a massive adversary.

Introduction

When Russia invaded Ukraine in February 2022, a hacktivist movement materialized almost overnight. Killnet — a group that had started as a paid DDoS-for-hire service targeting Russian government institutions — pivoted sharply, declared itself pro-Russia, and began coordinating attacks against hospitals, financial institutions, airports, and defense contractors across the United States and Europe. At its peak, Killnet's Telegram channels counted 120,000 members, with roughly 100,000 individuals actively contributing in some capacity to operations.

What made Killnet particularly dangerous wasn't sophistication — its DDoS attacks were often technically simple to mitigate. It was scale, propaganda, and the normalization of cyberattacks as a form of patriotism. Members of Russia's Duma publicly argued that hacktivists using "cyber weapons" for Russia should be exempt from military conscription. The Russian government didn't just tolerate Killnet; it celebrated it.

Alex Holden, founder of Hold Security and a Ukrainian-born cybersecurity veteran based in Milwaukee, decided to do something about it. What followed was a three-step counteroperation that ultimately unraveled one of the most prominent hacktivist organizations of the modern era.

The Rise of Killnet: From DDoS Shop to Hacktivist Army

▶ Watch: Killnet's origins and pivot to pro-Russian hacktivism (04:00)

Killnet's evolution is striking. Starting as a commercial DDoS service, the group made an audacious early move by targeting Russian law enforcement and government agencies to demonstrate its capabilities. Then, on February 23, 2022 — a single day before Russia's invasion of Ukraine — Killnet rebranded entirely as a pro-Russia hacktivist movement and immediately began going after the Anonymous collective.

What fueled its sudden growth was a wave of unemployed Russian IT workers. When Western companies exited the Russian market and severed ties with local employees, tens of thousands of technically skilled individuals found themselves jobless overnight. Many joined Killnet not out of ideological conviction, but for personal payback against former employers. Network engineers who understood the full TCP/IP stack could maximize DDoS bandwidth far more effectively than typical threat actors. Application developers brought Layer 7 attack expertise.

The group's reach was amplified by pure propaganda mechanics. Holden noted that one Killnet Telegram post described a member's grandmother clicking "reload" repeatedly on her Microsoft Edge browser, believing she was contributing to a DDoS operation — and in the Killnet ecosystem, she was. Killnet made hacktivism feel accessible, almost domestic.

Their attacks extended beyond technical disruption. The group photoshopped images of Lockheed Martin and Boeing executives in caskets, threatening them for supporting Ukraine with weapons. One documented call for action explicitly targeted US hospitals and ended with the Russian phrase "Kill them first."

Killmilk: The Face Behind the Operation

▶ Watch: Profile of Killnet's leader Killmilk (10:01)

Killnet's leader operated under the handle "Killmilk" — real name Nikolai Serafimov. On the surface, he presented as a young Russian patriot and aspiring musician. His social media showed military service photos, patriotic imagery, and a public persona as a defender of Russia.

The reality Holden uncovered was considerably different. Court records from 2018 showed Serafimov convicted under Article 228.1, Part 5 of the Russian Criminal Code — a drug dealing statute requiring a minimum sentence of eight years. Yet within a year of his 2018 conviction, Serafimov was out of prison, communicating publicly, and taking out personal loans. Holden's conclusion: Serafimov had cooperated fully with Russian law enforcement and been effectively recruited as an informant, likely working for the Russian state well before Killnet reached its peak.

By 2022, Serafimov was at the top of his game organizationally — but the cracks were already present. In an anonymous interview with Russian propaganda magazine Arte in October 2022, he publicly thanked a group called "Solaris" for Killnet's success. Solaris was a major Russian illegal drug marketplace. That acknowledgment was the opening Holden needed.

Operation Against Solaris: Hitting Killnet's Financial Backer

▶ Watch: The Solaris operation explained (18:02)

Hold Security had been monitoring Solaris for years. Holden explained that his firm tracks cybercriminals partly by following their drug purchasing activity on dark web markets — threat actors often use the same handles, and since most Russian drug buyers purchase close to home, Hold Security can triangulate physical locations. In Solaris's case, they had gone further: when the platform's operator, known as "Zanzi," reached out asking for help fixing PHP code, Hold Security quietly installed a backdoor on one of the servers — one that survived undetected for several years.

By the time Killmilk thanked Solaris publicly, Hold Security had full visibility into the platform, including the ability to track Zanzi's cell phone movements around Moscow — shopping centers, restaurants, daily routines.

The counteroperation had three stages. First, Hold Security logged into the Solaris platform and jerry-rigged it to redirect one day's worth of cryptocurrency revenues — approximately four Bitcoins — to a Ukrainian charity providing heating assistance to elderly civilians whose electricity had been destroyed by Russian strikes.

The operation made the front pages of Forbes. Solaris's public denial was almost comical: "We were not breached. Somebody just logged in." Within weeks, Holden's team published a complete dump of Solaris's source code, forum data, and transaction records. Rival dark web markets immediately seized on the chaos, and Solaris never recovered its position. The platform ceased to exist entirely roughly a year later.

Killnet's Internal Collapse

▶ Watch: Killnet's disintegration and Killmilk's downfall (24:02)

The Solaris exposure had a ripple effect inside Killnet. Once Killmilk's drug cartel funding became public, the Russian government — which controls Russian media — turned on him. State-controlled outlets ran pieces doxing Serafimov completely, publishing his home address and personal details.

Financially, the collapse was swift. Serafimov had owned four vehicles between himself and his wife at the start of 2023, including BMWs and a Porsche Panamera. By mid-year, he was pawning them all and taking out microloans in amounts small enough to pay for a manicure. His attempted restructurings of Killnet — firing everyone, restarting under a new name, handing control to an alias called "Backside" who turned out to be himself under a previous handle — all failed to regain momentum.

In October 2023, Killmilk posted what appeared to be a ceasefire announcement, claiming Killnet would no longer attack civilian targets. Twenty-four hours later, Hamas attacked Israel, and within another day Killmilk was calling for attacks against Israeli targets — abandoning any pretense of the pledge almost immediately.

The final irony: the Killnet Telegram channel, which Killmilk eventually sold, is now operated by new management that uses it to fight illegal Russian drug trafficking — apparently attempting to curry favor with Russian authorities. As Holden noted with dry humor: "I think we set a good example."

Notable Quotes

"Killnet at its highest point had 120,000 members within their Telegram channels. And almost 100,000 individuals actually contributed in some way toward this hacktivist collective."

— Alex Holden, ▶ 08:01

"We log in into the Solaris platform, and we jerry-rig it so, for a day, it's actually depositing all the money and helping folks in Ukraine to weather the rough winter — elderly people who could not depend for themselves."

— Alex Holden, ▶ 18:02

"This is not only a story about Russian hacktivism. It's also about finding the Achilles' heel — with this very small team of dedicated folks, all of them from Ukraine, who were able to take out this herd of wild animals and stop them quite successfully."

— Alex Holden, ▶ 30:03

Key Takeaways

  • Hacktivism has been normalized at a geopolitical scale. Russia's use of Killnet as a state-adjacent cyber weapon created a template that has since been replicated by actors in the Middle East, South Asia, and elsewhere — often with little meaningful national-level retaliation.
  • Leverage isn't always technical. Hold Security's decisive move wasn't a sophisticated hack; it was using years of pre-positioned access and deep intelligence on Killnet's financial relationships to strike where the organization was most vulnerable.
  • Criminal networks fund hacktivist operations. The explicit link between Solaris — an illegal drug marketplace — and Killnet's operational funding demonstrates that cybercrime ecosystems and state-adjacent hacktivism are more intertwined than commonly understood.
  • Propaganda is a weapon that can backfire. Killnet's entire operational model depended on the perception of invincibility and patriotic purpose. Once that narrative cracked — through public exposure of its leadership's criminal history and financial dependency on drug money — the organization's cohesion unraveled rapidly.
  • Small, motivated, well-placed teams can defeat massive collectives. The Hold Security operation against a 100,000-member hacktivist organization was run by a small team, all Ukrainian, leveraging intelligence gathered over years of patient work.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This is the counterop story I've been waiting to hear in public. Holden and a small Ukrainian team found the Achilles' heel of a 100,000-member hacktivist collective — not through superior technical power, but through patient pre-positioned access to their drug cartel financier. Real ops, real results, real geopolitical consequences.

Heather Calloway (CISO) — SOLID

A compelling first-person account of asymmetric counteroperation against a state-adjacent hacktivist group, with genuine strategic insight about finding leverage through financial dependency rather than technical capability. The lessons for defenders at most organizations are limited, but the intelligence about how hacktivist organizations are structured and funded is genuinely useful.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons