Zyklon
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Zyklon, also tracked under the alias Hell, has been observed operating since at least early 2015. Public reporting associates the actor with the group or moniker WonkaSec, indicating a collaborative or affiliated relationship. Geolocation information available in open sources points to China as the actor’s likely base of operations. Zyklon’s activities have been documented primarily through posts on Pastebin and temporary file‑hosting services where they advertised compromised data. The actor’s public persona is characterized by the signing of hacks with the tagline “Hacked By Zyklon #Wonkasec”.
Targeting appears opportunistic rather than limited to a single industry, with victims spanning educational institutions, online retail, and community forums. One notable incident involved the compromise of a Russian‑history subdomain at Macalester College, where user names, email addresses, and plaintext passwords were exfiltrated. Another campaign targeted aquamarineboat.com, an inflatable‑boat retailer, resulting in the theft of customer names, postal and email addresses, and credentials stored in clear text. The actor also breached the forum of Big Blue Interactive, although the exact volume of data taken from that site remains unclear due to the removal of related Pastebin entries. Additional compromises reported in the same timeframe include differencegames.com and en.asiadcp.com, each yielding thousands of usernames and associated plaintext passwords.
Observed tactics involve exploiting web‑application vulnerabilities to gain unauthorized access to backend databases containing user information. After obtaining the data, Zyklon typically exports the records and publishes them on Pastebin or similar text‑sharing platforms, sometimes accompanied by screenshots of the compromised site’s administrative panels. The actor makes use of temporary hosting domains—such as trippletoaster.freeiz.com—to store larger dumps that are referenced from the initial Pastebin posts. No specific malware families or custom tooling are mentioned in the available reports; the emphasis is on web‑based intrusion and credential dumping rather than payload delivery. Public notifications from sites such as DataBreaches.net have been issued to urge victims to reset passwords and to remove the leaked material from the hosting services.
Incidents
Attributed incidents are available to members.
6 incidents