CSIDB logo
Threat actor

Siph0n

Attribution profile

Type
Undetermined
Location
-
Known incidents
1 incident
First seen
2016-04-08
Last seen
2016-04-08
Updated
2026-07-15 23:11
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor referenced in the source material is known by the aliases Siph0n, Pyopz, and siph0n. These names appear in the metadata of the leaked email collections hosted on the hacked‑emails domain. No other identifiers or real‑world names are supplied in the available articles. The aliases are presented exactly as they were recorded in the leak filenames. This constitutes the entirety of the identifiable information about the actor within the provided context.

The three articles that accompany the leak entries are identical promotional pieces for Constella Intelligence, a company that offers digital risk protection services. They describe the company's data assets, monitoring capabilities, and service offerings rather than any malicious activity. Consequently, the texts do not mention any victim sectors, geographic regions, or strategic objectives attributed to the actor. There is no reference to financial gain, espionage, disruption, or any other motive within these documents. The content is strictly focused on the defensive capabilities of the vendor.

Because the source material lacks any description of the actor's behavior, no typical targeting patterns can be derived from the information given. No sectors such as finance, healthcare, or government are indicated as being of interest. Likewise, no regional focus is mentioned that would allow an inference about preferred operational theaters. The absence of details about initial access vectors, malware families, or tooling prevents any statement about the actor's technical methods. Similarly, no affiliations with state sponsors, criminal consortia, or hacker groups are presented in the articles.

In the absence of concrete evidence, no notable campaigns or publicly reported operations can be linked to the aliases Siph0n, Pyopz, or siph0n. The leak filenames themselves do not provide timestamps of attacks, victim names, or exfiltrated data details. Therefore, any attempt to outline specific incidents would rely on information outside the scope of the provided context. The only verifiable fact remains the existence of the aliases within the leak repository. No further details about the actor are available from the supplied sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB