CSIDB logo
Threat actor

v0g3lSec

Attribution profile

Type
Activist
Location
United States of America
Known incidents
1 incident
First seen
2022-03-03
Last seen
2022-03-03
Updated
2026-08-01 20:24
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias v0g3lSec is a hacktivist group that has been publicly linked to the Anonymous movement. Open‑source reporting indicates the group operates from the United States of America. Their observed activity focuses on Russian targets, specifically the Space Research Institute (IKI) which conducts scientific work for space experiments. The March 3 2022 incident shows the actor breached a subdomain of IKI, defaced the web page and released a ZIP file containing alleged internal documents. By defacing the site and distributing the leaked material, the actor demonstrated objectives that include service disruption and information disclosure. The defacement message referenced the International Space Station and the Russian government's decision to end its partnership with NASA.

The actor’s tactics, as seen in this operation, involve gaining unauthorized access to a web subdomain, altering its content to display a defacement message, and exfiltrating data for public release. The stolen data were packaged in a ZIP file and uploaded to a cloud storage service, with a link shared via Twitter. Responsibility for the hack was claimed through the Twitter handle @v0g3lSec and amplified by the Anonymous‑associated account @YourAnonNews. No specific malware families, exploit kits or initial‑access vectors were disclosed in the public reports, so the actor’s tooling style is limited to web‑based defacement and data‑leak techniques. The leaked ZIP reportedly contained PDFs, handwritten forms, descriptions of lunar missions and spreadsheets, though the authenticity of the material has not been independently confirmed. Other subdomains of the institute remained online during the attack, indicating a targeted rather than widespread disruption. The March 2022 breach of the Russian Space Research Institute remains the only publicly documented campaign attributed to v0g3lSec. This operation highlights the actor’s focus on high‑profile governmental or scientific entities within a geopolitical context.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB