Menu
Browse

Cyber Threat Actor: Catalin Dragomir

Actor Type Location Known Incidents
 Icon
Criminal
Romania
1 incident
Profile

Catalin Dragomir, also known by the alias Catalin Dragomir, is a Romanian individual who has been identified as a hacker involved in the unauthorized access and sale of access to computer networks located in the United States. He resides in Romania and was apprehended there before being extradited to face charges in the United States. Public records describe his activities as centered on gaining illicit entry to networks and then offering that access for payment, primarily using cryptocurrency as the transaction medium.

The targeting observed in the reported incidents includes government entities, specifically the emergency management department of the state of Oregon, as well as additional unspecified victims across the United States, with at least ten other networks compromised. The strategic objective demonstrated in these actions is financial gain, as Dragomir advertised the acquired administrative access for sale, negotiated a payment of three thousand dollars in Bitcoin, and provided proof of access by sharing samples of personal data such as employee login credentials, names, email addresses, and Social Security numbers. No publicly available information links his activities to espionage, disruption, or state‑sponsored motives.

The tactics, techniques, and procedures evident from the case involve obtaining unauthorized network access, validating that access by repeatedly entering the compromised environment, and then marketing that access to prospective buyers through illicit channels. The transaction was conducted using Bitcoin, indicating a reliance on cryptocurrency for anonymity in financial exchanges. There is no mention of specific malware families, exploit kits, or particular tooling styles in the disclosed sources. Attribution is confined to an individual Romanian national; law enforcement has not asserted any connection to a state actor or a larger criminal consortium, and the case proceeded as a solitary prosecution. The most notable operation cited is the 2021 intrusion into Oregon’s emergency management network, which served as a representative example of his broader pattern of selling access to multiple U.S. victims and resulted in aggregate losses exceeding two hundred fifty thousand dollars.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources