CSIDB logo
Threat actor

@Apex_Haxor

Attribution profile

Type
Hacker
Location
Russia
Known incidents
1 incident
First seen
2015-04-20
Last seen
2015-04-20
Updated
2026-08-28 17:40
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

@Apex_Haxor is a threat actor known by the alias @Apex_Haxor and, according to available open‑source information, is believed to be based in Russia. The actor first came to public attention in April 2015 when, under the banner of #OpIsrael2015, they defaced the Israeli news site calcalit‑tamar.co.il and exfiltrated approximately 1,200 records. This operation demonstrated a hacktivist motive aimed at disrupting online platforms associated with geopolitical targets. A later incident reported in September 2022 involved the actor allegedly compromising the website of the media outlet Fast Company, where they replaced the homepage with defacement messages and subsequently used the compromised content management system to push obscene and racist push notifications via Apple News. Both episodes show a pattern of targeting media and news organizations, with the apparent strategic objective of causing reputational harm and spreading disruptive content rather than pursuing financial gain or espionage.

The actor’s tactics, as described in the Fast Company case, rely on exploiting weak credentials: they located a WordPress instance used by the victim, logged in with a default password, and then abused authentication tokens to create administrator accounts. With administrative access they were able to modify site content and abuse the Apple News push notification service to disseminate malicious messages to followers. No specific malware families, exploit kits, or custom tooling are mentioned in the sources, indicating that the actor’s tooling style leans toward leveraging readily available administrative functions and publicly accessible services. Attribution to a state sponsor or a formal criminal consortium is not evident from the reported material; the only geographic clue is the possible Russian location noted in the actor’s profile. Consequently, the actor appears to operate as an individual or loosely affiliated hacktivist who utilizes simple credential‑based intrusions to achieve disruption‑focused outcomes against media‑sector targets.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB