Obnoxious and Pein
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases Obnoxious and Pein has been observed operating from the United States of America. The group first came to public attention in mid‑2016 when it claimed responsibility for a series of account takeovers targeting prominent YouTube creators. Their activity is limited to the incidents described in publicly available reports, with no further attribution to larger organizations or state sponsors.
In the June 25 2016 operation Obnoxious and Pein gained access to the YouTube channels of WatchMojo and Redmercy, renaming thousands of video titles to display hacking messages that included a reference to their Twitter handle. The same attackers also seized control of the associated Twitter and PayPal accounts of the Redmercy channel owner, demonstrating an ability to move across social media and financial platforms. While YouTube and PayPal access were eventually restored, the compromised Twitter account remained suspended after repeated hijacking attempts.
The reported method of initial access relied on credential reuse; the victim admitted using the same password across YouTube, Twitter, and PayPal, which allowed the attackers to pivot from one service to another. Despite two‑factor authentication being enabled on all affected accounts, the attackers were able to bypass this protection, suggesting they exploited the reused credentials rather than employing malware or custom tooling.
Public sources do not establish any clear affiliation with a state actor, criminal consortium, or larger hacking collective for Obnoxious and Pein. Consequently, their operational structure, size, and any potential strategic objectives beyond the observed incidents remain undetermined based on the available information.
Incidents
Attributed incidents are available to members.
2 incidents