B0yzTeam
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as B0yzTeam, also referred to as Boyztm, operates from Brazil according to publicly available reporting. The group first came to attention in September 2016 when they compromised a municipal website in the United States. Their activity is characterized by defacement of online assets coupled with extortion attempts. The actors identify themselves through a Portuguese language message and an image from the television show SouthPark left on the defaced page. No further details about their internal structure or recruitment are provided in the source material.
In the observed incident, B0yzTeam targeted the Bremerton Housing Authority, a government agency responsible for public housing assistance in Washington State. The attackers gained access to the agency’s web server, altered the site’s content, and placed a demand for six Bitcoin, which at the time corresponded to roughly four thousand United States dollars. Alongside the defacement they sent an email threatening to release the compromised database, which contained client names and the last four digits of Social Security Numbers, if the ransom was not paid. The group’s tactics therefore include website defacement, direct email extortion, and the use of cryptocurrency for payment. No malware families, exploit kits, or specific tooling are mentioned in the reporting, limiting the description of their technical repertoire to these observed actions.
Attribution beyond the geographic clue of Brazil is not established in the available sources, and no links to state sponsors or larger criminal consortia are cited. The Bremerton Housing Authority case stands as the sole publicly reported operation attributed to B0yzTeam in the provided material, representing a single extortion campaign rather than a series of incidents. The housing authority refused to meet the demand, contacted the Federal Bureau of Investigation, and issued a security advisory to its clients while rebuilding the affected system with improved safeguards. This outcome illustrates that the group’s attempt to monetize the intrusion was unsuccessful in that specific instance. No further activities or subsequent campaigns involving B0yzTeam are described in the supplied context.
Incidents
Attributed incidents are available to members.
0 incidents