j0shua3w
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias j0shua3w has been identified as operating from Brazil and is associated with hacktivist activities that emerged in 2015. Public reporting links this alias to a series of website defacements targeting Brazilian government and corporate entities, with the actor framing the intrusions as protests against perceived systemic corruption and inadequate digital defenses. The actor’s actions are described in open sources as motivated by a desire to question the nation’s cybersecurity posture and to highlight concerns about foreign surveillance, particularly referencing the NSA. No evidence in the provided material indicates financial gain or espionage as a primary goal, and the actor’s size, sophistication, or internal structure remains unspecified.
Targeting appears focused on Brazilian institutions, specifically a government research institute responsible for astronomy, geophysics, and metrology, as well as a major conglomerate involved in engineering, chemicals, construction, and petrochemicals. The sectors affected include public research and private industry, both located within Brazil, and the attacks were limited to website defacement rather than data theft or disruption of services. Strategic objectives cited in the sources involve exposing corruption within the government and large corporations, supporting official investigations such as Operation Lava Jato, and challenging the perceived ease with which foreign intelligence agencies could exploit national vulnerabilities. The actor’s messaging explicitly connected the defacements to broader hacktivist campaigns against the Odebrecht corporation over its role in the Petrobras scandal.
The only tactics, techniques, and procedures described are the defacement of web pages, with no reference to malware families, specific initial access vectors, or specialized tooling beyond the ability to compromise and alter online content. Attribution to a state sponsor or criminal consortium is not established in the available information, and the actor remains publicly unaffiliated with any known group beyond the alias j0shua3w and occasional mention of the handle ProtonWave in related Odebrecht actions. Significant campaigns documented include the compromise of the domains intranet.on.br and euler.on.br belonging to the Brazilian Institute of research and development in Astronomy, Geophysics and Metrology of Time and Frequency MCTI, and the September 2015 defacement of Odebrecht’s official website, both of which were subsequently restored. These incidents illustrate the actor’s pattern of using website defacement to convey political messages while avoiding more destructive or financially motivated methods.
Incidents
Attributed incidents are available to members.
1 incident