Russian Server
Attribution profile
- Type
- Criminal
- Location
- Portugal
- Known incidents
- 2 incidents
- Sources
- 0 sources
- First seen
- 2023-09-27
- Last seen
- 2023-09-27
- Updated
- 2026-07-31 03:21
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor knownby the alias Russian Server has been observed operating from Portugal. It has directed its activity against a Portuguese municipal administration, specifically the town hall of Gondomar. The targeting appears focused on local government entities within the country. No broader sectoral pattern is indicated in the available reporting.
In the September 2023 incident the actor gained initial access by compromising a Russian‑hosted server that served as a pivot point into the victim’s network. Once inside, it deployed ransomware that encrypted files and rendered systems unusable. The attackers then issued a ransom demand of €750,000, which the municipality refused to pay following official guidance. Concurrently, they exfiltrated sensitive data including citizen identification numbers and financial records, later publishing that information on the dark web.
The ransomware attack caused extensive operational disruption, prompting the town hall to revert to paper‑based processes while recovery efforts proceeded. Restoration involved replacing disks and reinstalling software on approximately 90 % of the 900 affected computers, a effort that required an estimated €1.5 million in investments. Although most devices were returned to service, certain online functionalities remained unavailable for an extended period, with full normalization expected only months after the attack. Authorities continue to investigate the intrusion’s timeline and underlying motives.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 0 sources.