Cursed Patriarch
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases VSOP, devil and Cursed Patriarch is associated with operations originating from Russia, as indicated in the supplied context. This actor has been linked to multiple distinct campaigns that showcase a willingness to employ different coercive techniques for financial gain. The aliases appear in various reporting sources that tie the actor to ransomware, distributed denial‑of‑service extortion and data‑theft incidents, suggesting a flexible approach to monetizing unauthorized access.
Targeting observed in the attributed incidents spans several sectors and geographic regions. A ransomware operation attributed to the Onix group—identified with the VSOP/devil/Cursed Patriarch persona—struck the Guatemalan foreign affairs ministry in September 2022, encrypting and corrupting files across dozens of government websites and demanding a ransom payment. In October 2021 the same actor, using the Cursed Patriarch moniker, launched a coordinated DDoS extortion campaign against a cluster of privacy‑focused email providers such as RiseUp, Posteo, Runbox, Fastmail, Kolab Now, Guerilla Mail, Mailfence and TheXYZ, demanding 0.06 BTC to cease network‑level disruption. Earlier that year, in December 2020, the actor exploited an authentication flaw in Twitter’s Android client to harvest email addresses and phone numbers linked to 5.4 million accounts, later offering the harvested data for sale. These cases demonstrate a pattern of targeting governmental entities, privacy‑oriented service providers and large social‑media platforms, with objectives that include extortion payments, direct financial profit from data sales and service disruption as a means of coercion.
The actor’s observed tactics, techniques and procedures reflect this varied targeting. The ransomware incident involved file‑encryption malware that rendered larger files unrecoverable even after payment, indicating a destructive element alongside the extortion demand. The DDoS extortion campaign relied on high‑volume volumetric attacks, with peaks reaching 256 Gbps, and reportedly leveraged the Meris botnet to generate the traffic volume needed to overwhelm target networks. The Twitter data‑theft operation stemmed from an authentication bypass in the mobile application that allowed the actor to associate submitted contact information with account identifiers and subsequently scrape public profile details, a technique that did not rely on malware but on exploiting a flaw in the platform’s security controls. No specific malware families beyond the Onix ransomware reference are mentioned in the source material, and no explicit exploit kits or custom tools are described.
Attribution information provided in the context is limited to the actor’s known location in Russia; no public statements tie the group to a state sponsor or a larger criminal consortium. Consequently, any assertion about state affiliation, hierarchical structure, revenue streams or technical sophistication would exceed the supplied evidence. The profile therefore remains confined to the observed aliases, the geographic origin, the sectors and objectives demonstrated in the reported incidents, and the concrete TTPs that have been documented in those operations. This constitutes a factual summary based exclusively on the information given.
Incidents
Attributed incidents are available to members.
10 incidents