sup3rm4n
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias sup3rm4n operates from Brazil and has been linked to hacktivist activities that target both government and private sector entities within the country. The actor’s known actions include the compromise and defacement of domains belonging to the Brazilian Institute of research and development in Astronomy, Geophysics and Metrology of Time and Frequency (MCTI), specifically intranet.on.br and euler.on.br, as well as the official website of the Odebrecht conglomerate. These intrusions were carried out to highlight perceived weaknesses in national cyber defenses and to question the government’s readiness against foreign espionage, particularly referencing the NSA’s surveillance capabilities. In the Odebrecht incident, the actor joined a broader hacktivist message demanding an end to alleged corporate theft from citizens and expressing support for the ongoing Lava Jato investigation into corruption. The stated strategic objectives therefore center on political protest, accountability, and raising awareness about perceived corruption and inadequate digital protections rather than financial gain or traditional espionage.
The actor’s observed tactics involve gaining unauthorized access to web servers, replacing legitimate content with defacement pages that contain Portuguese‑language messages, and preserving proof of the intrusions through zone‑h mirror links. No specific malware families, exploit kits, or initial access vectors are described in the available sources, and the activity is limited to website defacement rather than persistent malware deployment or data exfiltration. Attribution to any state sponsor, criminal consortium, or larger organized group has not been publicly established; the actor appears to operate as part of a loosely affiliated hacktivist milieu that includes the ProtonWave collective mentioned in the same reporting. The most notable publicly reported operations are the simultaneous defacement of the MCTI research institute’s domains in October 2015 and the Odebrecht website defacement in September 2015, both of which were subsequently restored by the victims. These episodes illustrate the actor’s focus on symbolic disruption aimed at prompting public discourse on governance and cybersecurity in Brazil.
Incidents
Attributed incidents are available to members.
1 incident