GrenXPaRTa
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as GrenXPaRTa also operates under the alias Gren Siahaan. Publicly available information indicates that the actor is based in China. These identifiers appear across multiple social media posts and blog entries linked to the intrusions. The actor uses the same handle when claiming responsibility for data leaks.
Observed activity shows a focus on online services located in the United Kingdom and a government website in Nigeria. The UK targets include a dating platform and a lottery service, while the Nigerian target is a national assembly portal. This pattern suggests the actor selects victims across different sectors such as social networking, online gambling, and government administration. No explicit statement of financial, espionage, or disruptive motives is present in the source material.
In one incident the actor disclosed credentials from approximately seven thousand three hundred seventy nine user accounts on a UK dating site. Another operation resulted in the release of nine thousand seven hundred two usernames and passwords from a UK lottery website. A separate breach involved the exfiltration of roughly forty nine megabytes of data from the Nigerian nation assembly’s web domain. In each case the actor published the stolen data and advised affected users to change their passwords.
The sources do not provide any detail about the malware families, exploit tools, or initial access vectors employed by GrenXPaRTa. Likewise, there is no publicly attributed connection to a state sponsor, criminal syndicate, or hacker collective. Consequently, the actor’s technical capabilities and affiliations remain unspecified in the referenced reports. No further details about the actor’s methods or affiliations are present in the supplied material.
Incidents
Attributed incidents are available to members.
4 incidents