Mark Nsd
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the alias Mark Nsd.
Open‑source reporting associates this alias with a location in Russia.
The actor first appeared in public reports in connection with a distributed denial‑of‑service attack against the email marketing service Mad Mimi on March 30, 2014.
No further historical activity under this alias is documented in the supplied sources.
On the date of the attack Mad Mimi’s network was flooded with traffic that severed connectivity between its servers and the Internet.
Shortly after the flood began the actor sent an email demanding 1.8 Bitcoin, worth roughly eight hundred thirty United States dollars at the time, to stop the assault.
The message warned that the attack would continue unless payment was received and offered a 24‑hour window for a response.
Mad Mimi refused to pay, implemented mitigation measures, and reported that the attack was halted after the actor indicated a temporary pause while awaiting a reply.
The company noted that it experienced intermittent service disruptions during the recovery, partly due to security upgrades and network‑provider issues, while emphasizing that customer data remained safe.
Mad Mimi contacted law enforcement and publicly stated that it would not negotiate with criminals, aligning its stance with other firms such as Meetup and Basecamp that had faced similar extortion attempts.
The targeting observed in this case was limited to a software‑as‑a‑service provider specializing in email marketing, indicating a focus on online service platforms.
No additional industry sectors or geographic regions are explicitly linked to Mark Nsd in the available material.
The apparent strategic objective was financial gain, as demonstrated by the direct Bitcoin ransom demand.
The tactics described consist of launching a volumetric DDoS flood followed by a plain‑text extortion email; no malware families, exploit kits, or specific tooling are mentioned in the reporting.
Consequently, details about initial access vectors, persistence mechanisms, or post‑exploitation tooling cannot be derived from the sources.
Public attribution to a state sponsor, criminal syndicate, or any other organized group has not been established for the actor using the alias Mark Nsd.
The Mad Mimi incident remains the sole operation confidently tied to this alias in the open‑source record, serving as the representative example of the actor’s known activity.
While the same article references contemporaneous DDoS extortion attempts against Meetup and Basecamp, it does not connect those events to Mark Nsd.
Therefore, any broader campaign or affiliation involving the actor remains undetermined based on the supplied information.
Incidents
Attributed incidents are available to members.
1 incident