Rocky Paul
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Rocky Paul is an alias associated with a threat actor who has been linked to disruptive online activity targeting media organizations. The name appears in open‑source reporting concerning a specific cyber incident that occurred in late December 2023. No additional aliases or organizational affiliations have been publicly attributed to this actor in the available sources.
On December 22 2023, the Balkan Investigative Reporting Network (BIRN) was subjected to a distributed denial‑of‑service attack that flooded its website with excessive traffic, rendering the site temporarily inaccessible. The attack followed BIRN’s publication of articles that examined fraudulent copyright claims connected to the convicted Turkish fraudster Yasam Ayavefe. The reporting detailed previous attempts to suppress content through legal and financial pressure, as well as earlier cyber incidents aimed at silencing coverage of Ayavefe’s activities.
The observed tactic in this incident was a volumetric DDoS assault, which seeks to overwhelm a target’s network resources and disrupt service availability. No malware families, exploit kits, or specific initial‑access vectors were referenced in the reporting, and the actor’s tooling style beyond the use of traffic‑generation techniques remains unspecified. The effect of the attack was a temporary loss of online access for the BIRN platform, illustrating a disruption‑oriented outcome.
Historical context provided in the same source indicates that this DDoS event mirrors earlier attacks against BIRN and its partner media outlets that occurred after investigations into Ayavefe’s acquisition of honorary citizenship despite his criminal record. These prior incidents similarly aimed to impede the outlets’ ability to publish content, suggesting a pattern of using denial‑of‑service tactics to challenge media scrutiny. No further details about the actor’s broader objectives, affiliations, or subsequent operations are publicly available.
Incidents
Attributed incidents are available to members.
1 incident