Angel_of_Truth
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Angel_of_Truth is the alias used by a threat actor whose known location is Canada. The actor has been observed targeting a Canadian mining company, indicating a focus on the natural resources sector within North America. Their stated motivation, communicated in both Russian and English, was retaliation against Canada for imposing sanctions on Russia and for supporting Western policies, framing the intrusion as a response to perceived geopolitical alignment. Rather than pursuing financial gain, the actor sought to exert political pressure by threatening further attacks unless Canada altered its foreign‑policy stance, using the disclosure of stolen information as leverage. No public attribution to a state sponsor or criminal consortium has been made, and the actor’s affiliations remain unspecified in the available sources.
The most extensively documented operation attributed to Angel_of_Truth involved a prolonged cyber intrusion against Detour Gold Corporation that began in April 2013 and persisted for over two years. During this period the actors maintained unauthorized access to the corporate network and exfiltrated a broad range of sensitive data, including employee records, medical complaints, disciplinary reports, supervisors’ personal information, incident documentation and details of gold shipments. Portions of the stolen data were subsequently released publicly, accompanied by warnings that additional leaks would follow if the demanded policy changes were not met. The breach was discovered after the actor posted a paste explaining their motives, prompting the victim’s IT security team to launch an investigation. No specific malware families, initial‑access vectors or tooling techniques are described in the referenced material, so those aspects of the actor’s tradecraft are not included here. The Detour Gold incident stands as the sole publicly reported campaign that illustrates the actor’s method of combining data theft with overt political messaging to achieve coercive objectives.
Incidents
Attributed incidents are available to members.
1 incident