Armada Collective
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Armada Collective, also known as DD4BC, is a threat actor linked to Russia that has carried out distributed denial‑of‑service extortion campaigns demanding Bitcoin payments to halt attacks. The group’s primary motive, as stated in multiple incident reports, is financial gain through ransom demands, and it has repeatedly targeted financial services, cryptocurrency services, secure email providers, and web‑hosting companies across Europe, North America, and Asia‑Pacific regions. Notable victims include YesBank India, MoneyGram, Braintree, Venmo, the New Zealand stock exchange, the Bitcoin wallet provider BitGo, the web‑host Moonfruit, and secure email services such as Neomailbox, Hushmail, and ProtonMail.
The actor’s tactics consistently involve high‑volume DDoS attacks that peak at up to 200 Gbps, employ rapidly changing attack vectors, and focus on critical infrastructure such as API endpoints, DNS servers, backend systems, and upstream ISP networks. In several campaigns the group has used multi‑vector assaults and advanced persistent denial‑of‑service techniques, with some incidents described as involving a second, more sophisticated stage that targeted weaknesses in ISP infrastructure and was described by victims as exhibiting capabilities more commonly associated with state‑sponsored actors. Ransom payments have been demanded in Bitcoin, and victims have reported that paying did not guarantee cessation of the attacks.
Prominent campaigns include the August 2020 extortion wave against YesBank India, MoneyGram, Braintree, Venmo, the New Zealand stock exchange and other financial processors, where the group threatened prolonged outages unless Bitcoin was paid. Earlier operations include a June 2016 DDoS against the BitGo Bitcoin wallet provider that disrupted transaction processing for hours, a December 2015 attack on the web‑host Moonfruit that forced the takedown of customer websites for up to twelve hours, and a November 2015 series of attacks on secure email providers such as Neomailbox and Hushmail that combined volumetric floods with sophisticated upstream ISP exploitation, one of which led to a ProtonMail incident where a $6,000 Bitcoin ransom was paid before subsequent attacks continued. While some analyses have suggested that a second, more sophisticated wave of activity in the ProtonMail case may involve state‑sponsored actors, no definitive attribution beyond the actor’s aliases and Russian location has been publicly confirmed. The group’s activity demonstrates a persistent focus on financially motivated DDoS extortion against high‑value online services.
Incidents
Attributed incidents are available to members.
11 incidents