CSIDB logo
Threat actor

Exfocus

Attribution profile

Type
Criminal
Location
Mexico
Known incidents
2 incidents
First seen
2015-09-30
Last seen
2015-12-24
Updated
2026-07-31 06:16
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Exfocus is the alias used by a hacker who has been linked to a series of distributed denial‑of‑service attacks against educational institutions in the United States. The actor is known to operate from Mexico, according to publicly available references.

Exfocus primarily employs a large botnet to generate volumetric traffic that overwhelms target networks. The botnet is reported to consist of more than eighty‑five thousand compromised machines capable of producing attacks around twenty‑five gigabits per second. This tooling style relies on sheer traffic volume rather than custom malware or sophisticated intrusion techniques. Early claims described the traffic as medium‑scale despite the later assertion of a 25 Gbps capability. The actor’s actions have been motivated by financial gain, as evidenced by payments received in Bitcoin from a client who commissioned the attacks. In interviews, Exfocus stated that additional compensation would be earned if the victim organization contracted a DDoS mitigation provider, indicating a clear financial incentive tied to the victim’s defensive spending. Beyond monetary reward, the attacks caused significant disruption to online services, including internet access, credit‑card processing, and learning‑management systems at the targeted university.

The most documented campaign involved repeated assaults on Rutgers University in 2015, where the actor claimed responsibility for five of six attacks within a year. During that period, Rutgers invested three million dollars in network upgrades, mitigation services, and a new internet provider after earlier disruptions. The actor’s activity prompted the university to increase its cybersecurity budget, which was reported to have contributed to a tuition increase. Despite those investments, the attacks continued to knock the campus offline, demonstrating the effectiveness of the botnet‑based approach. Law‑enforcement became involved after the sixth attack remained unclaimed, highlighting the seriousness of the threat. No public sources tie Exfocus to a state sponsor or a larger criminal consortium, and the actor’s affiliations remain limited to the individual hacker operating under this moniker.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB