CSIDB logo
Threat actor

Unit 02616 of Uzbekistan’s National Security Service

Attribution profile

Type
Nation State
Location
Uzbekistan
Known incidents
6 incidents
First seen
2019-10-31
Last seen
2019-10-31
Updated
2026-08-01 02:16
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is identified as Uzbekistan’s National Security Service (NSS), also referenced in open sources as Unit 02616. The group is publicly linked to the development of a custom hacking framework called Sharpa, which was first reported in October 2018. Open‑source reporting ties the unit to the country’s security apparatus and describes it as a state‑affiliated offensive cyber unit. Aliases used in public reporting include the NSS designation and the Sharpa development team.

The actor’s publicly documented targeting focuses on individuals perceived as critical of the Uzbek government inside the country. Reports cite journalists, human‑rights activists and other dissidents as the primary victims of its cyber operations. The stated purpose of these intrusions is to gather compromising material that can be used to discredit or silence critics of the authorities. This aligns with a strategic objective of conducting espionage and surveillance to suppress domestic opposition rather than pursuing financial gain. No public attribution ties the group to financially motivated cybercrime or to disruption of critical infrastructure outside the stated domestic focus.

Technical details disclosed in open sources are limited to the group’s acquisition of commercial spyware and its in‑house development effort. The NSS unit is reported to have purchased off‑the‑shelf hacking tools from vendors while simultaneously building its own framework. The custom framework, named Sharpa, was first observed in October 2018 and is described as a toolset for compromising computers and mobile phones. No specific malware families or exploit kits are named in the reporting; the emphasis is on the procurement of external tools and the Sharpa project. Initial access vectors are not detailed in the source material, so no specific vectors such as phishing or exploits can be confirmed from the available information.

Attribution to the Uzbek state is explicit in the reporting, with the unit described as part of the National Security Service. No linkage to criminal syndicates or foreign state sponsors is presented in the open sources consulted. Notable activities referenced include the October 2018 inception of the Sharpa framework and the documented purchase of commercial spyware capabilities. The group’s operations have been reported as internally focused, targeting Uzbek journalists, activists and dissidents to collect compromising material for discrediting purposes. This pattern of domestic surveillance and influence operations constitutes the primary publicly known campaign associated with the actor.

Incidents

Attributed incidents are available to members.

6 incidents
CSIDB