SonnySpooks
Attribution profile
- Type
- Criminal
- Location
- Russia
- Known incidents
- 7 incidents
- Sources
- 1 source
- First seen
- 2016-03-10
- Last seen
- 2016-07-12
- Updated
- 2026-08-01 00:33
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
SonnySpooks is the alias used by a threat actor whose location has been identified as Russia in open‑source reporting. The actor first appeared in public disclosures in early 2016, carrying out a series of website compromises that involved the exfiltration of user credentials and, in some cases, website defacement. Publicly attributed incidents include the breach of fijilive.com in May 2016, where 91,460 usernames and hashed passwords were dumped, the defacement and credential dump of paypalsucks.com in May 2016, and the compromise of buzzmachines.com in March 2016, which resulted in the release of nearly 37,000 usernames and passwords. These events were documented in sources such as Twitter posts, the SecurBay threat‑intelligence roundup, and the hacked‑emails.com leak repository.
The actor’s targeting appears to focus on publicly accessible websites rather than specific industrial or governmental sectors, with victims ranging from a Fiji‑based news site to a criticism‑oriented domain and a general‑interest blog. For the paypalsucks.com incident, the accompanying summary explicitly states that the motivation was notoriety and revenge, describing the defacement as an attempt to embarrass or harm the site’s owners rather than to pursue financial gain. While the fijilive.com and buzzmachines.com breaches are described as resulting in the theft of username and password hash data, the accompanying summaries do not declare a specific motive, so any inference about financial or espionage intent would exceed the provided information. The actor’s strategic objectives, therefore, are only definitively known for the paypalsucks.com operation, where notoriety and revenge were cited.
Observed tactics, techniques, and procedures consist of website defacement and the extraction of credential databases containing usernames and password hashes; no particular malware families, exploit kits, or command‑and‑control frameworks are mentioned in the available sources. Attribution beyond the geographic indication of Russia is not present in the material, and no links to state‑sponsored groups or criminal consortia are explicitly stated. Representative operations that illustrate the actor’s activity include the fijilive.com credential dump, the paypalsucks.com defacement accompanied by a credential leak, and the buzzmachines.com username‑and‑password dump, each reported in mid‑2016 and reflecting a pattern of targeting online platforms for data exposure or reputational harm. This summarizes the factual information available about SonnySpooks without speculation beyond the supplied sources.
Incidents
Attributed incidents are available to members.
7 incidentsSources
Sources available to members: 1 source.