Börteçine Siber Tim
Attribution profile
- Type
- Activist
- Location
- Russia
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2016-01-16
- Last seen
- 2016-01-16
- Updated
- 2026-08-01 00:09
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the aliases Brteine Siber Tim and Börteçine Siber Tim, names that appear in open‑source reporting related to cyber activity between Turkey and Russia. Contextual information indicates the actor is associated with Russia, while the article describing the embassy defacement notes that the group claimed to be based in Azerbaijan. The actor is described as a Turkish hacktivist collective that took responsibility for the defacement of the Russian Embassy’s website in Israel, aligning itself with broader cyber hostilities between the two nations. No explicit state sponsorship or criminal consortium affiliation is cited in the available sources.
Targeting observed for this actor includes government entities such as the Russian Embassy in Israel and the Instagram account of the Russian Communications and Mass Media Minister Nikolay Nikiforov, as well as financial infrastructure exemplified by the Central Bank of Russia and a sports organization represented by the Lokomotiv Moscow football club. The strategic objectives demonstrated in these incidents are primarily disruptive, involving website defacement, social media account takeover, and distributed denial‑of‑service attacks intended to impair availability and convey political messages. No publicly reported activity points to financial gain or espionage as a motive for this group.
The actor’s tactics, techniques and its tactics rely on defacement of web pages, hijacking of social media accounts, and the execution of DDoS campaigns, with no mention of specific malware families or custom tooling in the referenced material. Notable operations include the January 16 2016 defacement of russianembassy.org.il displaying Turkish, Turkmeni and Azeri insignia, the subsequent compromise of a Russian minister’s Instagram account, and DDoS attacks directed at the Central Bank of Russia and Lokomotiv Moscow. These actions were framed as responses to geopolitical tensions, particularly the downing of a Russian aircraft by Turkey, and were carried out while no comparable Russian‑aligned hacking groups were observed conducting counterattacks at that time.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.