CSIDB logo
Threat actor

ALTDOS

Attribution profile

Type
Criminal
Location
China
Known incidents
11 incidents
First seen
2020-11-01
Last seen
2021-09-15
Updated
2026-08-28 16:12
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

ALTDOS is a threat actor group that operates under the alias ALTDOS and has been linked to activities originating from China, although no direct state sponsorship has been publicly demonstrated. The group first came to wider attention through a series of data‑theft and extortion incidents reported across Southeast Asia in 2020 and 2021. Their public statements consistently describe their motivation as purely financial, emphasizing that they seek monetary compensation rather than political or ideological goals.

ALTDOS primarily targets organizations within the Association of Southeast Asian Nations (ASEAN) region, with observed victims in Malaysia, Singapore, Thailand, Bangladesh and, to a lesser extent, India. The sectors they have hit include real estate, consumer electronics retail, furniture retail, media and content conglomerates, securities trading firms, broadband providers and large conglomerates spanning multiple industries. Their strategic objective is to acquire sensitive data—such as personal records, financial information and internal documents—and then leverage that data through extortion, threatening public disclosure unless a payment is made.

The group’s tactics, techniques and procedures reveal a preference for initial access methods that include brute force attacks, code injection and network sniffing, as described in their own communications. Rather than deploying traditional ransomware, ALTDOS typically exfiltrates data and then encrypts the stolen copies locally using AES‑256 encryption, a technique they have cited as a way to avoid the corruption risks associated with ransomware decryption. They employ a double‑extortion model, first threatening to leak the data and, if ignored, subsequently publishing portions of it on public file‑sharing sites while providing proof of compromise via screenshots, spreadsheets or short videos of directory access.

Public attribution does not tie ALTDOS to any specific government agency or known criminal consortium; the group remains unattributed beyond the geographic clue of China. Notable publicly reported operations include the compromise of a Malaysian conglomerate where student data was threatened for release, the intrusion into a Singapore‑based real estate holding company that led to a claimed data breach, the attack on a Thai broadband provider that resulted in the alleged theft of millions of customer records, and the breach of a Bangladeshi conglomerate from which hundreds of gigabytes of files, source code and databases were taken. These incidents illustrate the group’s repeated use of data theft for financial extortion across multiple ASEAN sectors.

Incidents

Attributed incidents are available to members.

11 incidents
CSIDB