SXUL
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
SXUL, also known by the alias USDoD, is a threat actor traced to the United States of America and has been publicly linked to several high‑profile cyber incidents. The actor first came to prominence in connection with the December 2023 breach of NationalPublicData.com, a Florida‑based consumer data broker, where threat actors identified as USDoD advertised and later leaked billions of records containing Social Security numbers, names, addresses, phone numbers and email addresses. The same alias was claimed by the actor in a Breachforums post offering the stolen data for $3.5 million, and the actor claimed responsibility for compromising the InfraGard program, an FBI‑run information‑sharing initiative. In addition to the 2023 data‑theft operation, SXUL has been attributed to the global WannaCry ransomware campaign of May 2017, which impacted organizations across multiple sectors, including the Harapan Kita Hospital in Jakarta and Renault’s manufacturing facilities in Europe. These attributions are drawn directly from the supplied incident overviews and the accompanying KrebsOnSecurity article that details the actor’s self‑identification and claims.
The actor’s observed targeting spans consumer data brokers, healthcare institutions, automotive manufacturers, telecommunications providers and government‑related entities, reflecting a pattern of opportunistic intrusion rather than a narrow sector focus. The tactics described in the attributed incidents include the use of phishing emails masquerading as invoices, job offers or security warnings to gain initial access, followed by the deployment of ransomware that encrypts files and demands Bitcoin payment for decryption. In the NationalPublicData case, the actor exfiltrated massive volumes of personal data and subsequently offered the stolen information for sale on underground forums, indicating a financially motivated approach that combines data theft for resale with ransomware extortion. No explicit state sponsorship or affiliation with a particular cybercrime consortium is stated in the source material, although the actor’s self‑identification as USDoD and claim of compromising InfraGard suggest a possible nexus with U.S.‑focused cyber‑criminal circles.
Notable operations linked to SXUL include the 2023 NationalPublicData breach, which exposed hundreds of millions of personal records and led to a class‑action lawsuit and regulatory scrutiny, and the 2017 WannaCry ransomware outbreak that disrupted healthcare services at Harapan Kita Hospital halted production at Renault plants and affected numerous other organizations worldwide. These incidents illustrate the actor’s capability to conduct large‑scale data exfiltration for profit as well as to deploy widespread ransomware that causes operational disruption. The actor’s known location in the United States, the alias USDoD, and the claimed InfraGard compromise constitute the publicly available attribution details, while the described tactics—phishing‑based initial access, ransomware deployment, and monetization of stolen data through illicit markets—represent the consistent across the reported campaigns.
Incidents
Attributed incidents are available to members.
3 incidents