Meowless
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Meowless is a threat actor known by that alias and is associated with a location in Russia according to the provided context. The actor’s activities have been observed targeting governmental entities, specifically the Cluj County Council in Romania, as evidenced by a reported website compromise. The primary objective demonstrated in this incident appears to be financial gain, as the actors demanded a payment of $100 in Bitcoin to prevent the release of encrypted files. The attack resulted in the defacement of the council’s website, with a message indicating that all files had been encrypted and a backup saved, and that payment was required to avoid public disclosure of the data. No personal data was involved in the breach, as the council confirmed that the affected information consisted solely of public records.
The actor’s tactics, techniques, and procedures observed in this case include website defacement, file encryption, and the use of a cryptocurrency ransom demand delivered via a Bitcoin address. No specific malware families, initial access vectors, or tooling styles were described in the source material, so those details remain unspecified. Attribution beyond the stated Russian location is not publicly established, and no affiliations with state sponsors or criminal consortia are indicated in the available information. The Cluj County Council intrusion serves as a representative example of the actor’s publicly reported operations, illustrating a low‑value ransom scheme directed at a regional government target. The council’s response involved identifying the vulnerability, initiating remediation, restoring the site from backup, and optimizing its operation, after which the site returned to normal functionality.
Incidents
Attributed incidents are available to members.
0 incidents