31337
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases 31337 and Elitehacker has been linked to a 2017 operation that compromised personal accounts of a Mandiant employee. Open‑source reporting indicates the actor may be based in Russia, although this detail is not confirmed beyond the statement that the location is known if available. The actor first came to public attention when they leaked internal documents from FireEye’s Mandiant subsidiary and mocked the company on Pastebin. Their activity is characterized by a self‑described motive of pursuing pleasure rather than financial gain. No further biographical details about the actor are provided in the source material.
Targeting focused on the cybersecurity industry, specifically a Virginia‑based security firm and its employees, with the leaked material also affecting third‑party organizations such as an Israeli bank and an Israeli security company. The actor’s stated objectives included exposing confidential data, damaging the reputation of the targeted firm, and tracking security researchers and journalists as a form of personal challenge. Initial access was achieved by compromising the employee’s personal LinkedIn and Hotmail accounts, which then allowed the actor to pivot to internal documents. The actor used the Windows Find My Device feature to monitor the victim’s Surface Pro laptop and subsequently defaced the LinkedIn profile. Communication and publication of stolen data occurred through Pastebin posts that accompanied the leaks and included the hashtag #LeakTheAnalyst.
The operation dubbed #LeakTheAnalyst resulted in the release of multiple data dumps that contained a confidential forensics report from Illusive Networks, internal worksheets, network topology diagrams, and threat intelligence profiles related to the Israeli Defence Forces. One file was altered by the actor to overlay the campaign hashtag, demonstrating a deliberate effort to claim ownership of the leaked material. The Pastebin messages accompanying the dumps mocked FireEye’s public statements, accused the company of lying about the breach scope, and praised or criticized individual security researchers and journalists who had commented on earlier leaks. The actor claimed to have spent a year inside the employee’s computer before executing the leak, emphasizing a prolonged period of access. Despite the volume of sensitive information, FireEye maintained that its corporate networks showed no signs of intrusion and attributed the loss to the compromise of personal accounts.
Attribution to a specific state sponsor or criminal consortium is not evident in the publicly available reports; the only geographic clue is the unspecified reference to Russia as the actor’s location if known. No malware families, exploit kits, or custom tooling are described in the sources, limiting the technical profile to the use of credential theft, device tracking, and public paste sites for dissemination. The #LeakTheAnalyst campaign remains the sole publicly referenced operation associated with the aliases 31337 and Elitehacker. No further incidents or additional details about the actor’s infrastructure, size, or funding have been disclosed in the material provided.
Incidents
Attributed incidents are available to members.
1 incident