CSIDB logo
Threat actor

runningsnail

Attribution profile

Type
Hacker
Location
China
Known incidents
1 incident
First seen
2018-09-09
Last seen
2018-09-09
Updated
2026-07-30 22:10
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias runningsnail is associated with a location in China, as indicated in the available context. The actor first came to public attention on September 9 2018 when they exploited a smart contract vulnerability in the EOS‑based decentralized betting platform DEOSGames. Using a newly created account, the actor deposited 339 EOS, valued at approximately $1,695, and then triggered the platform’s jackpot 24 times within an hour, withdrawing 4,728 EOS worth about $23,640. The platform confirmed the incident as a malicious contract exploit and noted that most of the funds remained with the actor, who subsequently began interacting with other EOS betting decentralized applications.

The actor’s observed activity focuses on EOS‑based gambling dApps, indicating a targeting pattern that centers on decentralized finance applications built on the EOS blockchain. The demonstrated objective appears to be financial gain, as the actor converted a small initial deposit into a substantially larger payout through repeated exploitation of a contract flaw. The tactics described involve the creation of a fresh account, the deposit of a minimal amount of cryptocurrency, and the repeated execution of a vulnerable contract function to drain funds; no specific malware families, initial access vectors, or tooling styles are referenced in the source material. After the DEOSGames incident, the actor was seen experimenting with additional EOS betting dApps, suggesting a continued search for similar weaknesses.

The DEOSGames exploit followed a comparable vulnerability that had been exploited weeks earlier against the EOSBet.io platform, underscoring a recurring pattern of flaws in EOS smart contracts that attackers can leverage for profit. While the actor’s actions contributed to the loss of operating funds for the targeted dApp, the platform characterized the event as a stress test that prompted contract‑level improvements. The broader context notes that researchers have earned substantial bug‑bounty rewards for uncovering EOS vulnerabilities, highlighting the attractiveness of such flaws to both malicious actors and security professionals. No public attribution to state sponsors, criminal consortia, or other affiliations is provided in the available information.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB