Paw Security
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Paw Security, also referred to as PawSec, is a hacker collective that emerged in public view during August 2014. The group’s location is noted as China, though no more specific geographic details have been disclosed. Its activities were framed as a protest against perceived animal cruelty, with a particular focus on the treatment of dogs in China. A Pastebin manifesto attributed to the collective described its members as defenders of animals that are allegedly tortured, caged, and transported for slaughter. The collective identified itself through social media channels, most notably Twitter, where it announced its intentions and later claimed responsibility for the attacks.
The collective’s targeting encompassed Chinese government portals and a variety of state‑owned enterprises across several sectors. It specifically mentioned the official government website (gov.cn), the energy giant Sinopec Limited, the telecommunications provider China Mobile, and the online media corporation Sina Corp. Additional targets included the National Tobacco Corporation, the Hong Kong Post, and ministries overseeing Justice, Public Security, National Defense, Environmental Protection, and the Southern Power Grid Company, as well as the automotive manufacturer Zhongxing Automobile Co Ltd. Prior to the disruptions, Paw Security stated that it had scanned approximately three thousand Chinese websites for vulnerabilities to identify exploitable weaknesses. The ensuing actions resulted in temporary outages on the affected online services, which the group described as disruptive rather than destructive. Paw Security used its Twitter account to claim responsibility, characterizing the intrusions as retaliation against inhumane treatment of animals and presenting the operation as a form of hacktivist protest.
No public sources have linked Paw Security to a state sponsor, criminal consortium, or any larger hacking alliance, and the group’s affiliations remain unspecified. The August 2014 campaign represents the most extensively documented set of activities associated with the alias, with no subsequent large‑scale operations reported in open‑source reporting. Consequently, the known profile of Paw Security is limited to its observed hacktivist‑motivated website disruption efforts targeting Chinese governmental and corporate entities.
Incidents
Attributed incidents are available to members.
1 incident