Prosox
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Prosox, also referred to as Prosox Shade or simply Shade, has been observed operating from Russia. Public reporting identifies the actor’s primary aliases and notes a Russian geographic nexus. Observed activity shows the actor targeting the beverage industry and online media platforms, specifically compromising the Red Bull energy drink website and the Vevo‑managed YouTube channels of celebrities. In the Red Bull incident the actor exploited a recent Drupal remote‑code‑execution vulnerability to upload a file named adminer.php to thirty country‑specific subdomains. The uploaded adminer.php file functioned as a webshell that allowed the actor to replace legitimate web pages with attacker‑controlled content. After the initial upload, a second actor using the Shade moniker edited the same adminer.php files to add a “Hacked By Shade” note.
No public reports confirm that any data was exfiltrated during the Red Bull compromise. Prior to the Red Bull event, the actor gained unauthorized access to Vevo’s official YouTube account, enabling the alteration of video titles and the forced removal of popular videos such as “Despacito.” This Vevo compromise relied on credential abuse or account‑takeover techniques rather than a software vulnerability. The actor’s technical repertoire therefore includes exploitation of web‑application flaws and credential‑based takeover of online services. No public attribution links the actor to a state sponsor or a formal criminal consortium. The two most frequently cited operations are the April 2018 defacement of Red Bull’s Drupal‑based subdomains and the preceding Vevo YouTube‑channel takeover.
Incidents
Attributed incidents are available to members.
1 incident