CSIDB logo
Threat actor

vimproducts

Attribution profile

Type
Criminal
Location
China
Known incidents
4 incidents
First seen
2016-11-08
Last seen
2016-11-08
Updated
2026-08-01 01:54
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias vimproducts operates as a DDoS‑for‑hire service provider. According to publicly available reporting, the individual is based in China. The actor advertises and sells attack capacity through a dark web marketplace, specifically referencing a profile on AlphaBay. Pricing for the service is described as ranging from twenty‑five to one hundred fifty dollars per day depending on the target’s size and protection level.

Vimproducts has been observed targeting Russian financial institutions, including banks such as Rosbank, Alfa‑Bank and the Bank of Moscow, as well as the Moscow Exchange. These targets were selected during a period of heightened political tension surrounding the United States election in November 2016. The actor’s stated objective was to fulfill customer requests aimed at expressing dissatisfaction with Russia’s alleged electoral interference, while simultaneously using the attacks to promote his own DDoS‑for‑hire business. By seeking media coverage and giving interviews to outlets such as Motherboard, the actor aimed to gain publicity that would attract additional paying customers.

The reported tactics involve the execution of distributed denial‑of‑service attacks; no specific malware families or initial access vectors are described in the source material. The actor’s tooling style appears to rely on the rental of botnet capacity rather than the development or deployment of custom malware. Attribution to a particular state sponsor or criminal consortium has not been established in public reports, although the actor’s location is noted as China. No further affiliations or partnerships are mentioned in the available sources.

A representative operation occurred on 8 November 2016, when vimproducts claimed responsibility for DDoS attacks that rendered three of four targeted Russian banking sites—the Moscow Exchange, Bank of Moscow, Rosbank and Alfa‑Bank—inaccessible for approximately an hour. An attempted attack against the Russian Ministry of Economic Development’s website did not succeed in disrupting service. The actor highlighted the victims’ inadequate DDoS protections and used the incident to advertise the effectiveness and affordability of his service. The campaign concluded with the actor securing media attention that served to promote his DDoS‑for‑hire offering to prospective clients.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB