Menu
Browse

Cyber Threat Actor: Dohaeragon

Actor Type Location Known Incidents
 Icon
Sensationalist
Turkey
0 incidents
Profile

Dohaeragon is the alias used by an individual or group linked to Turkey, as indicated by the location information associated with the actor and the Turkish usernames of the team members identified in the defacement notice. The actor operates under the name Dohaeragon, which reportedly derives from the fictional High Valyrian term meaning “serve,” and is associated with the self‑described “Team Faceless Men” that includes individuals such as Polatbey, Morghon, SoloKing, Claronomes and KingOfNoobs. Publicly available references describe these members as Turkish gamers, with at least one having a documented profile showing a young age and a focus on popular online games. No further personal details or organizational affiliations for Dohaeragon have been disclosed in the source material.

The observed activity of Dohaeragon involved the defacement of a Kaiser Permanente‑related web site, specifically the Health Innovations subdomain that was externally hosted and not integrated into the Kaiser Permanente internal network. The target sector can be characterized as healthcare‑related information services, and the geographic focus of the activity aligns with the actor’s known location in Turkey. The defacement replaced the site’s intended content with a message claiming responsibility and included a reference to a Game of Thrones‑themed video, thereby disrupting the normal presentation of the site and preventing visitors from viewing the intended health‑innovation information. The article notes that, prior to the incident, the site had not been subjected to Kaiser Permanente’s usual security measures and had remained unpatched for an extended period, indicating that the initial access vector likely involved exploitation of an unpatched web application vulnerability. No malware families, specific tooling, or post‑exploitation behaviors are mentioned in the source material.

No public attribution to a state sponsor, criminal consortium, or larger hacking group has been established for Dohaeragon, and the actor’s activities have not been linked to any broader campaign beyond the single defacement event described. The Kaiser Permanente site defacement remains the only publicly reported operation associated with the alias, and the outcome was limited to the alteration of web page content without evidence of unauthorized access to protected health information or internal systems. The incident concluded with the site being moved to a different IP address by the victim organization, and no further actions attributed to Dohaeragon have been documented in the provided sources.

Incidents
Attributed incidents available to members
0 incidents
Sources
Sources available to members
1 source