Threat actor · all actors
FRwL (From Russia with Love)HACK-FROM-RUSSIA-WITH-LOVE hacktivist
🇷🇺 RU
aka FRwL (From Russia with Love), FRwL, Z-Team, UAC-0118, FromRussiaWithLove
Last updated: 2026-08-20
About this actor
From Russia with Love, is a threat actor group that emerged during the Russia-Ukraine war in 2022. They primarily engage in DDoS attacks and have targeted critical infrastructure, media, energy, and government entities. FRwL has been linked to the use of the Somnia ransomware, which they employ as a wiper rather than for financial gain. While there is no direct evidence linking FRwL to the Russian Main Intelligence Directorate, it is possible that they coordinate activities with state-aligned hacktivist groups.
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
CERT-UAUAC cluster id
Unclassifiedno scheme matched
How we know this
- Data origin
- Curated overlay Hacktivist entry synthesised from public reporting — not a MITRE-tracked intrusion set.
- Techniques
- No ATT&CK techniques mapped.
- Named victims
- None on file.
Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
No techniques attributed.
Co-occurring actors
None.
Similar actors
Same nation-state
Same category
- Moses Staff 1.00
- Al-Toufan 1.00
- AnonOps 1.00
- Anonymous Brasil 1.00
- Anonymous Collective 1.00