Chrichir
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Chrichir, also using the alias ChrichirTheGod, has been active in mid‑March 2015. Open‑source reporting indicates the actor is based in Australia. The actor operates under a single pseudonym and has claimed to work alone in the incidents attributed to them. Their online presence includes a Twitter handle (@ChrichirTheGod) used to announce compromises and to communicate with victims. No additional aliases or affiliations have been publicly disclosed in the available sources.
The actor’s observed targets are educational institutions, specifically colleges and vocational training providers. Incidents have been recorded in Australia (South West Institute of TAFE and FIT College) and the United States (University of Oklahoma). The primary initial access vector described in the reports is SQL injection against web‑facing applications. After gaining access, the actor has posted screenshots, database listings, or links to Pastebin to demonstrate the breach. These disclosures are accompanied by direct tweets to the compromised institutions’ official accounts.
On 12 March 2015 the actor tweeted that South West TAFE’s server had been accessed via SQLi and posted a screenshot as proof. On 18 March 2015 the actor released a Pastebin list of FIT College’s databases and told interviewers they had inspected thousands of student and payment records. On 11 March 2015 the actor used SQLi to reach internal systems at the University of Oklahoma and shared details of private communications they had viewed. In all three cases the actor stated that they did not download or exfiltrate the underlying personal data. The actor’s public messages focused on the ease of re‑exploiting the flaws and the victims’ lack of response to their notifications.
Incidents
Attributed incidents are available to members.
3 incidents