Killing Killnet
Alex Holden
DEF CON 33 · Day 3 · Main Stage
Overview
Killnet was one of the most publicly visible Russian hacktivist groups of the post-2022 era. With a Telegram channel in the tens of thousands of followers, regular appearances in Russian state media,

Key moments
- 16:21 Introduction: Killnet DDoS hacktivist group overview
- 3:38 Killnet's major DDoS operations and claimed targets
- 5:54 Technical infrastructure behind Killnet attacks
- 8:38 Attribution analysis: who is behind Killnet
- 10:54 Real effectiveness of Killnet attacks vs. propaganda
- 13:38 How Killnet was disrupted and effectively neutralized
- 15:54 Lessons learned about countering hacktivist DDoS groups
- 18:38 Future of pro-Russian hacktivist operations
Killing Killnet
Speakers: Alex Holden
Conference: DEF CON 33 (Las Vegas, August 8, 2025)
YouTube: https://www.youtube.com/watch?v=wVY47hNzgJk
Overview
Killnet was one of the most publicly visible Russian hacktivist groups of the post-2022 era. With a Telegram channel in the tens of thousands of followers, regular appearances in Russian state media, and a steady drumbeat of DDoS attacks against NATO governments, healthcare systems, financial institutions, and critical infrastructure, Killnet presented itself as a decentralized grassroots cyber movement aligned with Kremlin objectives. It was loud, chaotic, and — by design — difficult to attribute or confront.
It was also, largely, a performance.
At DEF CON 33, Alex Holden of Hold Security delivered a detailed post-mortem on how a team of nine analysts tracked Killnet, exposed its true structure, identified its critical financial dependency on a major Russian darknet drug marketplace, and executed a strategic disruption campaign that collapsed the group's funding, eroded its credibility, drove away Russian government support, and ultimately triggered the disintegration of Killnet as an operational entity.
This talk is not a traditional vulnerability disclosure or malware analysis. It is a case study in threat actor research, OSINT-driven infiltration, strategic pressure, and the kind of asymmetric cyber intelligence work that rarely gets documented in public. Holden's personal background — born in Kyiv, a refugee from the Soviet Union in 1989, monitoring Russian threat actors as a career — provides both the motivation and the context for why this work mattered beyond the technical.
Background
Killnet's Origins and Rise
Killnet was established in November 2021, initially as a DDoS-for-hire service. Within months, the February 24, 2022 Russian invasion of Ukraine transformed its operational profile entirely. The group rapidly repositioned as a politically motivated hacktivist collective, targeting countries and organizations perceived as opposing Russian interests: NATO member governments, European airports, US financial institutions, healthcare networks, and government portals across a dozen countries.
The group's public face was a figure operating under the alias KillMilk (later identified as Nikolai Nikolaevich Serafimov). KillMilk served as the group's loudmouth spokesman, conducting interviews with Russian state media outlet RT (Russia Today), issuing declarations of cyberwar, and cultivating the image of Killnet as a spontaneous mass movement of Russian patriots. A representative RT interview from October 9, 2022, captured KillMilk stating: "I have huge support from my friends at SOLARIS — this is also an aggressive and strong team from the Dark Web."
That offhand public mention of Solaris was one of the threads Hold Security began pulling.
What Killnet Actually Was
Holden's investigation determined that despite Killnet's decentralized public image, the group was operationally controlled by a small, identifiable core. The noise and apparent chaos were a deliberate cover: the group used high-volume propaganda and DDoS announcements to generate a perception of mass participation that obscured who was actually running operations and where the money was flowing.
The Russian government's relationship with Killnet appears to have been one of convenient deniability. Killnet could conduct low-level harassment operations against Russian adversaries while the state maintained plausible separation from a nominally independent hacktivist group. This was a normalized feature of the Russian state-adjacent threat actor ecosystem, not a coincidence.
Solaris: The Financial Link
Solaris was one of Russia's top three illegal drug marketplaces as of 2022. Established in 2017 by a figure known as "Zanzi," it operated over 1,000+ drug shops across Russia by its peak and was embedded in the Russian darknet economy at significant scale. KillMilk's public endorsement of Solaris on RT was not a casual aside — Holden's research established that Killnet had a genuine financial dependency on Solaris infrastructure and revenue.
This connection was the Achilles heel. Solaris was a criminal enterprise with technical infrastructure: Bitcoin payment systems, Zabbix monitoring, Ansible automation, Tor infrastructure, Solaris Exchange, anti-DDoS services, WireGuard VPNs, and community forums. This infrastructure left exposure — and Hold Security's team systematically developed access to it.
Key Findings
- Killnet was not decentralized. The group was controlled by a small identifiable leadership, with KillMilk (Nikolai Nikolaevich Serafimov) at its center. The decentralized appearance was deliberate information operations.
- Killnet's critical financial dependency was Solaris, a Russian darknet drug market. This created a single point of failure that could be targeted without directly attacking Killnet's own (more hardened) infrastructure.
- Hold Security gained access to Solaris infrastructure, ultimately exposing: Tor nodes and DDoS guards; monitoring frameworks; the Solaris catalog and shop Git repositories (full source code); MongoDB forum data dumps; and SQL database content from individual Solaris shops.
- The disruption strategy was multi-layered: expose the Solaris-Killnet link publicly; compromise Solaris's operational stability; leak data that undermined trust within both organizations; and divert cryptocurrency proceeds (from Solaris) to a Ukrainian charity — an act that generated internal Russian outrage and delegitimized Killnet in the eyes of its own claimed constituency.
- The cascade effects: Russian government withdrew financial support from Killnet; KillMilk went broke; Killnet attempted an unsuccessful pivot to for-profit operations; the group publicly "disbanded," then changed hands, then issued contradictory calls for peace and war in rapid succession. KillMilk was ultimately doxed by Russian media itself — a sign that even domestic state allies had turned on him. As of early 2025, Killnet does not exist as a functional entity.
- The unintended consequence: Killnet's collapse did not end the threat. Russian state operators, having observed the experiment with deniable hacktivist proxies, drew lessons about operational security and vetting. More tightly controlled, better-vetted successor groups emerged — a pattern consistent with the maturation of state-sponsored cyber operations.
Technical Deep Dive
Intelligence Collection Against Solaris
Hold Security's approach to Solaris was methodical. The darknet marketplace was an attractive intelligence target precisely because:
- It was commercially motivated, with extensive technical infrastructure and record-keeping
- Its operators prioritized operational uptime and reliability over operational security
- Its connection to Killnet provided leverage not just against a drug market but against a geopolitically relevant threat actor
The technical infrastructure Hold Security mapped and eventually penetrated included:
Bitcoin ecosphere: Transaction tracking linked Solaris financial flows, allowing correlation between platform revenue and downstream disbursements — including to Killnet-affiliated accounts.
Zabbix monitoring: The presence of a Zabbix deployment revealed internal network topology and host inventory. Zabbix instances that are not properly segmented frequently provide significant lateral movement opportunities.
Ansible automation: Ansible playbooks and inventory files, once accessed, reveal complete configuration management details for the platform — essentially a blueprint of the entire deployment.
Tor Infrastructure: Mapping Solaris's onion services and guard nodes provided deanonymization footholds.
Git repositories (Solaris Catalog and Shop source code): Complete source code access facilitates vulnerability identification, credential extraction, and understanding of authentication mechanisms across the platform.
MongoDB forums dump and SQL databases: User data, communications, and transaction records from shops constituted the evidentiary core for public disclosure.
The Solaris Disruption Sequence
Hold Security conducted two major rounds of Solaris disruption:
Round One: Initial exposure of the Solaris-Killnet connection. Solaris's response was initially dismissive — a statement claiming "nobody hacked us" and attributing reports to "provocation and manipulation." The catalog was taken offline for a week under the guise of a migration.
Round Two: A more comprehensive data release: Tor nodes and DDoS guards, monitoring framework, full Git source code, forum MongoDB dumps, and SQL databases from shops. This constituted a near-total exposure of Solaris's operational infrastructure.
Final Round: The Kraken marketplace takeover of Solaris, Zanzi's departure from the project, and Solaris's subsequent fade into irrelevance. The cryptocurrency diversion to Ukrainian charity — described as a deliberate act of symbolic sabotage — occurred in this period, generating significant internal Russian darknet community backlash against both Solaris and, transitively, Killnet.
KillMilk Deanonymization
Holden presented the identity reveal of KillMilk — Nikolai Nikolaevich Serafimov — as a key milestone. The deanonymization involved correlating public statements (including RT interviews), operational security mistakes in Killnet's own communications, and data obtained through the Solaris investigation. The subsequent doxing of KillMilk by Russian media (not Hold Security) was notable: it indicated that the Russian security establishment had made a deliberate decision to burn KillMilk rather than continue protecting him — a signal of how completely Killnet had lost its utility to the state.
Demo / PoC
The demonstration in this talk is primarily operational intelligence rather than a technical tool demo. Holden presented:
- Slide documentation of Solaris infrastructure showing the specific technical systems accessed
- The Solaris source code and database exposure timeline — showing what was obtained and when
- The Deanon Club takeover of Killnet branding after KillMilk's departure
- KillMilk's public unraveling — including the doxing by Russian media and his descent into irrelevance
The Hold Security blog documented portions of the Solaris exposure publicly: Hold Security Solaris Exposure Report (January 2023)
Defensive Implications
While this talk describes an offensive intelligence operation against threat actors rather than a defensive product, the case study carries significant implications for organizations and practitioners thinking about threat actor disruption, intelligence operations, and attribution:
Strategic disruption works. The Killnet case demonstrates that non-technical pressure points — financial dependencies, reputational exposure, relationship degradation with state patrons — can be more effective than purely cyber countermeasures against hacktivist groups. A DDoS mitigation service can suppress attacks; exposing the financial infrastructure supporting the group can prevent future attacks from ever being launched.
Criminal infrastructure creates intelligence exposure. Killnet's dependence on a darknet drug marketplace was its strategic vulnerability. Organizations studying Russian threat actors should maintain visibility into the darknet economy as part of their threat intelligence posture — criminal markets are not separate from state-adjacent threat actors.
Small teams can win asymmetric engagements. Nine analysts against an organization claiming 100,000 participants. The leverage came from identifying and targeting a single dependency rather than attempting to match scale.
Successor groups are the expected outcome. Killing Killnet did not kill the threat. It eliminated one poorly secured proxy and forced more professional, vetting-heavy replacement groups to emerge. This is consistent with the broader Russian state cyber ecosystem: removal of one element does not dismantle the capability; it refines it.
Attribution enables pressure. The deanonymization of KillMilk was not an end in itself but a precondition for the pressure campaign. Defenders investing in attribution capabilities — even partial attribution — gain leverage they can translate into disruptive action.
Key Takeaways
- Killnet was never the decentralized grassroots movement it presented itself as; it was a centralized, small-group operation using the appearance of mass participation as cover for state-aligned harassment operations.
- The group's financial dependency on Solaris (a Russian darknet drug marketplace) was its strategic vulnerability — one that a team of nine analysts at Hold Security identified and systematically exploited.
- The disruption campaign combined OSINT, technical penetration of Solaris infrastructure, strategic public disclosure, and cryptocurrency redirection to create a multi-vector pressure campaign that collapsed both Solaris and Killnet.
- The result was the complete operational disintegration of Killnet: loss of state support, severed financial channels, internal collapse, leadership deanonymization, and eventual abandonment of the brand.
- The more sobering conclusion is that Killnet's failure taught Russian operators to improve: successor groups are more tightly controlled and better vetted — meaning the next disruption campaign will require more sophisticated approaches.
About the Speaker
Alex Holden is the founder and Chief Information Security Officer of Hold Security, a cybersecurity firm specializing in threat intelligence and dark web monitoring. Born in Kyiv, Ukraine, he left the Soviet Union as a refugee in 1989 and has spent decades in cyber security with a focus on monitoring, infiltrating, and disrupting Russian cybercriminal and state-adjacent threat actor networks. He is best known for several major database breach exposures (including a 2014 Hold Security report on a 1.2 billion credential database held by Russian criminals) and for sustained investigation of threat actors with ties to Russian intelligence and organized crime. His background as a Ukrainian immigrant with deep Russian-language capabilities and understanding of former Soviet criminal and intelligence networks gives him access and analytical depth that few Western researchers can match. He presents regularly at major security conferences and has been widely quoted in coverage of Russian cyber operations. He can be reached at [email protected] and via @HoldSecurity on social media.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Holden documents how nine analysts at Hold Security identified Killnet's financial dependency on the Solaris darknet drug marketplace, systematically penetrated Solaris infrastructure, executed a multi-round data exposure campaign, redirected cryptocurrency to a Ukrainian charity, and triggered Killnet's operational collapse. Rare public documentation of a real threat actor disruption operation.
Heather Calloway (CISO) — MUST SEE
A detailed post-mortem on how nine analysts at Hold Security identified Killnet's critical financial dependency on a Russian darknet drug marketplace, penetrated that infrastructure, and executed a multi-vector disruption campaign that collapsed the group's funding, state support, and operational coherence. A case study in asymmetric pressure against state-adjacent threat actors.