Threat Group-4000
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Threat Group-4000, also known by the alias Threat Group-4000, is a cyber threat actor that has been observed operating from China. The actor first came to public attention through a series of incidents targeting educational institutions and a media networking provider. These incidents demonstrate a pattern of activity that includes unauthorized network access, deployment of malware, and the use of ransomware to disrupt services.
The actor’s known victims include several public school districts in the United States, such as a district near Albany, New York; Haverhill Public Schools in Massachusetts; Tangipahoa Parish schools in Louisiana; and multiple districts across Louisiana that prompted a state‑wide emergency declaration in July 2019. In addition to the education sector, the actor compromised Skyview Networks, a company that provides technical services and programming distribution to radio affiliates, causing interruptions to the CBS World News Roundup feed. All observed attacks occurred within North America, with no reported activity outside this region in the publicly available sources.
The tactics observed in these incidents involve gaining initial access to victim networks, after which the actor deploys malware that encrypts files or locks systems, a characteristic typical of ransomware attacks. In the school‑district cases, the malware forced the shutdown of phone lines, email systems, and office functions, and in some instances required the isolation of networks to limit spread. The Skyview Networks incident consisted of unauthorized access that interrupted technical services and disrupted the delivery of programming, indicating the actor can also operate without deploying encryption malware when the goal is service disruption. No specific malware families or tool names are mentioned in the source material, only the general use of ransomware and generic malware.
Attribution to a specific government sponsor or criminal consortium is not stated in the open sources; the only publicly available detail is the actor’s location in China. The alias Threat Group-4000 has been used consistently across the reported incidents, suggesting a single cohesive group rather than a collection of unrelated actors. Representative campaigns include the 2023 Skyview Networks breach, the 2021 ransomware attacks on Albany‑area and Haverhill school districts, and the 2019 Louisiana school‑district ransomware wave that triggered a state of emergency. These examples illustrate the actor’s repeated focus on disrupting operational continuity in both the education and media sectors.
Incidents
Attributed incidents are available to members.
5 incidents