Menu
Browse

Cyber Threat Actor: Börteçine Siber Tim

Aliases 2 aliases
Actor Type Location Known Incidents
 Icon
Activist
Russia
1 incident
Profile

Brteine Siber Tim, also known as Börteçine Siber Tim, is a hacking collective referenced in open‑source reporting as being affiliated with Turkish hacktivists and claimed to originate from Azerbaijan according to the article that details their activities, while the broader context lists their location as Russia. The group’s known aliases appear in Turkish‑language sources and are used interchangeably in the coverage of their operations. Their targeting has focused on Russian governmental and institutional assets, including the website of the Russian Embassy in Israel, the Instagram account of the Russian Communications and Mass Media Minister, the Central Bank of Russia, and the Lokomotiv Moscow football club, indicating a pattern of striking entities linked to the Russian state, media, finance, and sports sectors. The strategic objectives evident from these actions are primarily disruption and propaganda, as demonstrated by website defacements that displayed Turkish, Turkmeni, and Azeri insignia and by distributed denial‑of‑service attacks intended to impair online services. No explicit mention of financial gain or espionage motives is present in the supplied material, so the profile limits itself to the observed disruptive and symbolic aims.

The group's observed tactics, techniques, and procedures involve website defacement, social‑media account hijacking, and distributed denial‑of‑service campaigns, with no reference to specific malware families or custom tooling in the available sources. Initial access vectors described include exploiting web‑application vulnerabilities to alter embassy site content and compromising credentials to seize control of a minister’s Instagram account, followed by the use of traffic‑generation tools to overwhelm DNS infrastructure and corporate servers. Notable operations cited in the article comprise the January 16 2016 defacement of the Russian Embassy in Israel’s site, the subsequent takeover of the Russian minister’s Instagram account, and the DDoS assaults against the Central Bank of Russia and Lokomotiv Moscow, all attributed to Turkish hackers acting under the Börteçine Siber Tim banner. Affiliation details point to a loose hacktivist alignment rather than a formal state sponsor, as the reporting notes that no Russian‑aligned hacking groups engaged in counterattacks during the described cyber hostilities, leaving the conflict largely one‑sided in favor of Turkish‑origin actors. The attribution remains based on the group’s self‑claimed responsibility and the contextual linkage to Turkish hacktivist activity, without evidence of direct state direction or criminal‑consortium involvement.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
1 source