[email protected]
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
[email protected] is an email address that has been used as an alias by a threat actor linked to extortion activities. The actor is associated with Russia according to available location information. In March 2018 the actor sent an extortion message to JJ Meds, a medical marijuana delivery service operating in Canada.
The message demanded payment to prevent the release of customer information that had allegedly been obtained through a compromise of the JJ Meds website. The victim described the communication as an extortion threat and posted the full email on a public forum for awareness. The actor’s demand was accompanied by a claim that failure to pay would result in a leak of sensitive data. Following receipt of the threat JJ Meds took its website offline and removed all customer identifiers from the site. The company also engaged a security firm to eradicate malware and any other remnants of the intrusion from its web infrastructure.
These actions indicate that the actor had achieved some level of access to the JJ Meds web environment and had deployed malicious code there. The extortion email itself represents the primary initial contact vector used by the actor in this incident. No specific malware family or toolset is named in the reporting, only the generic reference to malware removal. The actor’s objective appears to be financial gain through the threat of data exposure, as the message explicitly requests funds to avert a leak. There is no publicly available information linking the actor to a larger criminal consortium or state‑sponsored group. The JJ Meds case remains the only publicly documented operation associated with the [email protected] alias. Consequently the actor’s known activity is limited to a single extortion attempt targeting a cannabis‑related business in North America. The incident highlights the use of email‑based extortion coupled with website compromise as a tactic for monetary gain.
Incidents
Attributed incidents are available to members.
0 incidents