CSIDB logo
Threat actor

Russian Server

Attribution profile

Type
Criminal
Location
Portugal
Known incidents
2 incidents
Sources
0 sources
First seen
2023-09-27
Last seen
2023-09-27
Updated
2026-07-31 03:21
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor knownby the alias Russian Server has been observed operating from Portugal. It has directed its activity against a Portuguese municipal administration, specifically the town hall of Gondomar. The targeting appears focused on local government entities within the country. No broader sectoral pattern is indicated in the available reporting.

In the September 2023 incident the actor gained initial access by compromising a Russian‑hosted server that served as a pivot point into the victim’s network. Once inside, it deployed ransomware that encrypted files and rendered systems unusable. The attackers then issued a ransom demand of €750,000, which the municipality refused to pay following official guidance. Concurrently, they exfiltrated sensitive data including citizen identification numbers and financial records, later publishing that information on the dark web.

The ransomware attack caused extensive operational disruption, prompting the town hall to revert to paper‑based processes while recovery efforts proceeded. Restoration involved replacing disks and reinstalling software on approximately 90 % of the 900 affected computers, a effort that required an estimated €1.5 million in investments. Although most devices were returned to service, certain online functionalities remained unavailable for an extended period, with full normalization expected only months after the attack. Authorities continue to investigate the intrusion’s timeline and underlying motives.

Incidents

Attributed incidents are available to members.

2 incidents

Sources

Sources available to members: 0 sources.

CSIDB