Palesa
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Palesa is an alias used by a threat actor whose known location, if any, is China. The actor first came to public attention in December 2019 when they claimed to have obtained source code files related to several AMD graphics processing units, including the Navi 10 and Navi 21 architectures and the Arden GPU associated with Microsoft’s next‑generation Xbox console. According to AMD’s statement, the perpetrator contacted the company asserting possession of test files for current and future graphics products, some of which were later posted on GitHub before being removed via a DMCA takedown request. The actor said they planned to sell the remaining material, stating a valuation of one hundred million dollars while acknowledging receipt of offers ranging from fifty thousand to one hundred thousand dollars. AMD confirmed the breach, launched an investigation with external experts and law enforcement, and maintained that the stolen intellectual property was not core to the competitiveness or security of its graphics products.
The only publicly reported targeting by Palesa involves the semiconductor sector, specifically a manufacturer of graphics processing units, indicating a focus on high‑value intellectual property within that industry. The actor’s apparent goal was financial gain, as evidenced by the attempt to monetize the stolen source code through a sale to the highest bidder. No details about malware families, exploit tools, or initial access vectors have been disclosed in the available reporting; the actor merely asserted that the files were taken directly from AMD’s internal repositories. Consequently, no specific TTPs such as phishing, credential theft, or custom malware can be inferred from the source material. Attribution beyond the possible Chinese location remains unspecified, with no public linkage to a state sponsor or criminal consortium.
The December 2019 incident stands as the sole documented operation attributed to Palesa, representing a notable case of source code theft from a major GPU developer. While AMD downplayed the impact, the episode highlighted the risk of insider or external threats targeting proprietary design assets in the technology sector. The actor’s actions prompted a coordinated response involving the victim company, external forensic experts, and law enforcement agencies, illustrating the typical escalation path for such intellectual property breaches. No further campaigns or linked activities have been reported in open sources, leaving the actor’s subsequent behavior unknown.
Incidents
Attributed incidents are available to members.
1 incident