Cyber Threat Actor: Russian Server
| Actor Type | Location | Known Incidents |
Criminal
|
Portugal
|
2 incidents |
|---|
Profile
The threat actor knownby the alias Russian Server has been observed operating from Portugal. It has directed its activity against a Portuguese municipal administration, specifically the town hall of Gondomar. The targeting appears focused on local government entities within the country. No broader sectoral pattern is indicated in the available reporting.
In the September 2023 incident the actor gained initial access by compromising a Russian‑hosted server that served as a pivot point into the victim’s network. Once inside, it deployed ransomware that encrypted files and rendered systems unusable. The attackers then issued a ransom demand of €750,000, which the municipality refused to pay following official guidance. Concurrently, they exfiltrated sensitive data including citizen identification numbers and financial records, later publishing that information on the dark web.
The ransomware attack caused extensive operational disruption, prompting the town hall to revert to paper‑based processes while recovery efforts proceeded. Restoration involved replacing disks and reinstalling software on approximately 90 % of the 900 affected computers, a effort that required an estimated €1.5 million in investments. Although most devices were returned to service, certain online functionalities remained unavailable for an extended period, with full normalization expected only months after the attack. Authorities continue to investigate the intrusion’s timeline and underlying motives.
