CSIDB logo
Threat actor

CyberZeist

Attribution profile

Type
Activist
Location
India
Known incidents
4 incidents
First seen
2016-11-08
Last seen
2016-12-22
Updated
2026-07-31 00:55
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

CyberZeist, also referenced as CyberZeist, is a threat actor known by the alias CyberZeist and has been linked to the Anonymous collective, with public references noting participation in an Anonymous operation against the FBI.GOV database in 2011. The actor has collaborated with the security researcher Kapustkiy on several operations, indicating a loose affiliation with individuals who identify as security testers or hacktivists. Public reporting shows targeting of government entities in the United States, Italy, and Hungary, as well as non‑governmental organizations focused on human rights, including the FBI.GOV domain, the Windham County Sheriff’s Office in Vermont, the Italian Dipartimento della Funzione Pubblica website, and the Hungarian Human Rights Foundation website. No public attribution to a state sponsor or criminal consortium has been presented in the sources reviewed.

The actor’s reported tactics, techniques, and procedures include the use of SQL injection to extract database contents, as described in the compromises of the Hungarian Human Rights Foundation site, the Italian government portal, and the Windham County Sheriff’s Office systems. In the FBI.GOV intrusion, CyberZeist exploited a Plone zero‑day vulnerability and accessed outdated FreeBSD 6.2‑RELEASE systems, additionally retrieving exposed backup files stored on the same server. No specific malware families or custom tooling are mentioned in the available material; the emphasis is on web‑application flaws and misconfigured assets. Campaigns highlighted in open‑source reporting include the November 2016 breach of the Hungarian Human Rights Foundation website, which exposed over 20 000 accounts containing personal data, the concurrent compromise of an Italian government site that yielded details of roughly 45 000 accounts, and the November 2016 leak of data from the Windham County Sheriff’s Office that included MD5 hashed passwords, plaintext credentials for per‑diem employees, and prisoner transportation records. The FBI.GOV intrusion, referenced in a 2016 article, involved extraction of data from a legacy FreeBSD system and the observation that an existing Plone zero‑day remained effective against the backend.

Across these incidents, the actor has communicated with the affected administrators, reported the identified flaws, leaked only a portion of the obtained data to provide the victims time to remediate, and subsequently removed the leaked material from public sites after the issues were addressed. This pattern of responsible disclosure coupled with selective data release is explicitly noted in the sources. No statements regarding financial gain, political sponsorship, group size, or technical sophistication appear in the provided material, and therefore such attributes are not included in this profile. The available evidence describes a loosely affiliated actor employing web‑application exploits to target governmental and NGO assets, engaging in limited disclosure before remediation.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB