CSIDB logo
Threat actor

Philippine Army

Attribution profile

Type
Nation State
Location
Philippines
Known incidents
3 incidents
First seen
2021-06-22
Last seen
2021-07-01
Updated
2026-08-01 01:16
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is publicly identified by the aliases Philippine Army and Armed Forces of the Philippines, with its base of operations located in the Philippines. Attribution to this actor rests on forensic analysis linking the infrastructure used in the attacks to the Department of Science and Technology and the Army’s Office of the Assistant Chief of Staff for Intelligence, a connection acknowledged by the Department’s undersecretary who confirmed sharing IP addresses with other government agencies. The actor’s known activities are directed against Philippine alternative media outlets such as Bulatlat and Altermidya, as well as the human rights organization Karapatan, indicating a focus on domestic information and advocacy sectors. The observed actions are characterized as disruptive, aiming to render target websites unreachable through traffic flooding rather than pursuing financial gain or espionage.

The actor’s tactics include conducting distributed denial‑of‑service attacks that flood victim networks with junk traffic, as seen in the sustained outages of Bulatlat and Altermidya’s websites. Prior to the denial‑of‑service phases, the actor performed vulnerability scans against the same targets using the Xerosecurity Sn1per tool, an automated scanner employed by penetration testers to map an organization’s attack surface. These scans originated from machines associated with the Department of Science and Technology’s IP ranges, suggesting the actor leveraged shared government infrastructure to conduct reconnaissance. No specific malware families or initial access vectors are described in the available sources beyond the scanning and traffic‑flooding activities.

A representative operation occurred between May and June 2021, during which Qurium Media Foundation documented brief but frequent denial‑of‑service incidents against Bulatlat, Altermidya, and Karapatan, culminating in a several‑hour outage on the night of June 22 2021. This campaign was accompanied by vulnerability scanning activity that traced back to government‑linked IP addresses, prompting a lawmaker to call for an investigation into alleged state‑sanctioned cyberattacks against critical media entities. The July 1 2021 reports of additional DDoS attacks on the same outlets further illustrate the actor’s repeated use of disruption tactics against Philippine media and human rights groups.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB