CSIDB logo
Threat actor

@SQLiNairb

Attribution profile

Type
Activist
Location
Russia
Known incidents
3 incidents
First seen
2014-02-13
Last seen
2014-02-13
Updated
2026-08-01 07:41
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the aliases nairb and @SQLiNairb has been observed operating under a moniker that appears in both underground forums and public leak announcements. Open‑source reporting indicates that the individual is believed to be based in Russia, although no further biographical details have been publicly confirmed. The actor’s public persona is tied to a single documented intrusion that took place in February 2014, which remains the primary source of insight into their capabilities and intentions.

In that incident the actor targeted the official website of the National‑Socialist Party of Canada, a far‑right extremist organization, and explicitly stated that the attack was motivated by opposition to the group’s racist and fascist ideology. The breach resulted in the exposure of 1,356 user accounts containing email addresses, usernames and passwords, alongside encrypted MySQL credentials and administrative login details lacking associated email addresses. By publishing a partial data dump on Pastebin accompanied by an anti‑racist message and later releasing a full set of five databases through MirrorCreator, the actor sought to undermine the organization’s operational security and to signal a warning to similar hate‑based entities. No indication of financial gain, espionage or profit‑driven motives appears in the reporting; the stated aim appears to be ideological disruption and public shaming.

The actor’s tactics, techniques and procedures, as evidenced by the 2014 compromise, consist of a rudimentary GET‑based MySQL injection that allowed unauthorized database access. No custom malware, exploit kits or advanced persistence mechanisms were reported; the intrusion relied on a simple SQLi vector to extract data. After exfiltration, the actor used widely available public platforms—Pastebin for an initial tease and MirrorCreator for the complete leak—to disseminate the stolen information, accompanied by a short taunting statement directed at the target’s supporters. This pattern suggests a preference for low‑complexity, publicly accessible tools to achieve visibility rather than covert, long‑term presence.

Attribution beyond the geographic hint of Russia remains unspecified, and no links to state sponsors, criminal syndicates or hacker collectives have been established in the public record. The National‑Socialist Party of Canada breach stands as the sole publicly documented operation associated with the handle @SQLiNairb, serving as the representative example of the actor’s activity. Consequently, the profile is limited to the confirmed facts of this single campaign, reflecting an individual who employs basic SQL injection to advance an ideological agenda against extremist groups.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB