CSIDB logo
Threat actor

Unbekannte

Attribution profile

Type
Criminal
Location
Germany
Known incidents
10 incidents
First seen
2013-08-01
Last seen
2024-01-06
Updated
2026-08-01 03:41
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the aliases Unidentified and Unbekannte, with a reported location in Germany. No further personal or organizational identifiers have been publicly disclosed in the available sources.

Observed activity spans a variety of sectors and geographic regions. Incidents have targeted financial institutions such as the National Bank of Angola, cryptocurrency platforms like Unibot, retail organizations including Ace Hardware and an Australian wine retailer, government entities ranging from a Pakistani police department to U.S. election officials, healthcare providers such as Indian Creek Foundation and Ochre Health Wollongong, technology firms exemplified by a major electronics manufacturer’s website, and automotive‑related sites like the compromised Citroën fan site. These events have occurred in Angola, the United States, Australia, Pakistan, and Germany, indicating a broad international reach.

The actor’s tactics demonstrate a mix of malware deployment, vulnerability exploitation, and social engineering. Notable examples include the use of the Emotet (Heodo) trojan delivered via compromised websites hosting malicious Word documents that required macro enabling, ransomware encryption affecting the Indian Creek Foundation network, credential‑phishing campaigns employing invoice‑themed emails with malicious links and spoofed government addresses, exploitation of an unpatched Adobe ColdFusion vulnerability to install a backdoor on the Citroën site, and the abuse of a newly implemented smart contract vulnerability to drain funds from Unibot. Additional methods involve unauthorized access through testing platforms, the installation of backdoors providing full server control, and the distribution of malicious JavaScript files alongside infected documents.

Public attribution does not link the actor to any specific state sponsor or criminal consortium; the only confirmed detail is the possible German location. Representative operations that illustrate the actor’s range include the 2024 incident against the National Bank of Angola, the 2023 Unibot cryptocurrency theft, the 2021 Emotet‑laden website compromise, the 2021 FBI‑warned credential‑phishing wave targeting election officials, the 2019 Ochre Health Wollongong disruption, and the 2013 Citroën ColdFusion breach. These cases collectively show a pattern of financially motivated theft, espionage‑oriented credential harvesting, and disruptive service interruptions across multiple industries and regions.

Incidents

Attributed incidents are available to members.

10 incidents
CSIDB