Prosox
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known publicly as Prosox operates as part of a duo that uses the online handles Kuroi’sh and Prosox on Twitter. The pair has been identified as being based in the United States of America. Their activity came to light in April 2018 when they claimed responsibility for compromising the Vevo YouTube channel. They describe themselves as hackers who seek to demonstrate that even large companies with presumed strong security can be breached.
The duo’s targeting has focused on media and entertainment platforms, specifically the Vevo video hosting service and the Twitter accounts of news outlets such as BBC Arabia and NowThis News. In their statements they indicated that the actions were carried out in support of Palestine, pointing to a politically motivated objective rather than financial gain. The defacement of video titles and the deletion of the Despacito music video served as a visible disruption of the targeted services. Their public messaging emphasized the ability to bypass security controls that organizations rely on.
Regarding tactics, the actors reported gaining control of Vevo’s administration server, which they described as being linked to a system they referred to as INVULP. They also mentioned the inclusion of something they called VRTMS, though the article does not elaborate on what these tools or systems entail. The compromise allowed them to alter video titles, delete content, and subsequently take over Twitter accounts to post messages. No specific malware families, exploit kits, or initial infection vectors are detailed in the source material.
Attribution information is limited to the actors’ self‑declared location in the United States; no public reports tie them to a state sponsor or a known criminal consortium. The article notes a prior breach of Vevo by the OurMine hacking group in September 2017, but it explicitly states that it is unclear whether that earlier incident facilitated the later activity of Kuroi’sh and Prosox. Consequently, the duo remains characterized as an independent pair of hackers operating under the aliases Kuroi’sh and Prosox.
Incidents
Attributed incidents are available to members.
0 incidents