NLB
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
NLB Team, also known simply as NLB, is a pro‑Ukrainian hacker group whose activities have been publicly linked to operations originating from Ukraine. The group’s aliases appear in multiple reports describing breaches of Russian entities, and the sources consistently characterize NLB as acting in support of Ukrainian interests. Their known targets include the education sector, exemplified by the Moscow Electronic School platform, and the retail sector, illustrated by the attack on the Russian chain Digital Network System (DNS). These incidents show a pattern of focusing on organizations that hold large volumes of personal data belonging to Russian citizens. The group’s stated alignment with Ukraine indicates a political or ideological objective rather than a financial one, as the disclosed motivations are framed in terms of supporting a geopolitical stance.
In both reported operations, NLB exploited security gaps in the target’s IT infrastructure to gain unauthorized access and exfiltrate personal information. For the Moscow Electronic School breach, the group obtained a database containing login credentials, full names, birth dates, SNILS numbers, email addresses, and phone numbers, affecting over three million unique individuals. In the DNS incident, the attackers accessed customer and employee details, including full names, usernames, email addresses, and phone numbers for approximately sixteen million people, while confirming that passwords and payment card data were not stored on the compromised systems and therefore were not taken. The sources do not reference any specific malware families, custom tooling, or particular initial access vectors beyond the exploitation of existing vulnerabilities, indicating that the group’s methodology relies on identifying and leveraging weaknesses in publicly facing services to extract data.
Attribution to a state sponsor is not explicitly stated in the available material; NLB is described solely as a pro‑Ukrainian hacker collective without evidence of direct government backing or affiliation with a criminal consortium. The group’s most notable campaigns are the December 2022 leak of the Moscow Electronic School database and the September 2022 DNS data exposure, both of which resulted in the public release of substantial personal data sets and prompted the affected organizations to acknowledge security shortcomings and initiate remediation efforts. These actions underscore NLB’s role in conducting data‑disclosure operations aimed at undermining confidence in Russian institutions while advancing a pro‑Ukrainian narrative.
Incidents
Attributed incidents are available to members.
2 incidents