CSIDB logo
Threat actor

CocaineSecurity

Attribution profile

Type
Hacker
Location
Russia
Known incidents
1 incident
First seen
2015-11-06
Last seen
2015-11-06
Updated
2026-07-31 19:07
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as CocaineSecurity has been referenced in open-source reporting. The alias CocaineSecurity appears in connection with a cyber incident against a Nordic financial institution. The actor’s location is noted as Russia in the available context. No additional names or alternate handles have been publicly attributed to this actor. The actor’s presence in threat intelligence is limited to the single reported event.

The reported activity targeted Swedbank, a major bank operating in Sweden. The Swedbank infrastructure belongs to the financial sector and serves customers across the Scandinavian region. The actor employed a distributed denial-of-service technique that overwhelmed the bank’s public website. As a result, online transaction processing via the website was halted while mobile applications and payment channels remained functional. The disruption was described as preventing customers from conducting business through the web portal.

No specific malware families, exploit kits, or initial access vectors were disclosed in the source material. Consequently, no tooling style or procedural patterns can be derived from the existing reports. Public sources do not establish any state sponsorship, criminal consortium affiliation, or other organizational links for CocaineSecurity. The Swedbank DDoS incident of November 2015 stands as the sole publicly documented operation linked to this alias. This event represents the entirety of the verified activity currently associated with CocaineSecurity.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB