holo-gfx
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias holo‑gfx has been linked to a cyberattack against the manga platform MangaDex that began on March 17 2021. According to public reporting, the actor is associated with Russia, although no further details about their identity or organizational ties have been disclosed. The actor gained unauthorized access to an administrator account by reusing a session token that had been exposed in an old database leak, taking advantage of a misconfiguration in the site’s session management. Using this token, the attacker obtained full control of the environment, downloaded the site’s source code, and subsequently published it on GitHub under the holo‑gfx moniker.
During the intrusion, the actor claimed to have identified and exploited a “file type confusion” vulnerability and indicated possession of a second, undisclosed flaw. They also asserted that they had dumped the MangaDex database, though they stated the data had not been released publicly. Throughout the incident, the actor taunted the platform’s developers by commenting on patches as they were applied and warned that additional remote code execution vulnerabilities and web shells remained in the codebase. These statements suggest the actor relied primarily on credential reuse and web application flaws rather than custom malware or sophisticated tooling.
Public sources do not establish any clear affiliation with a state sponsor, criminal consortium, or other threat actor group; the only attribution detail provided is the possible Russian location. Consequently, no state nexus or criminal consortium link can be confirmed from the available information. The actor’s activity appears limited to this single reported operation, with no other campaigns publicly attributed to the holo‑gfx alias.
The attack forced MangaDex to shut down its services while it worked on a more secure version of the platform, and the site warned users to assume that all account data had been compromised. Users were advised to change passwords on any other services where they might have reused their MangaDex credentials and to remain vigilant for potential phishing attempts should the alleged database dump ever be released. No further actions or claims by the actor have been documented in the sources provided.
Incidents
Attributed incidents are available to members.
1 incident