PeggleCrew
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
PeggleCrew is a hacking group that has been publicly referenced under that alias and is associated with a location in Russia according to available reporting. The group first came to attention in mid‑2016 when it compromised a software distribution platform, an act that was later described in detail by a news article archived from Softpedia. Public sources identify one of its members by the nickname “Cult of Peggle,” indicating that the crew operates as a small collective rather than a lone individual.
The group’s typical targeting appears to focus on software download sites and the end‑users who obtain popular free applications from those sites. In the Fosshub incident PeggleCrew exploited an unauthenticated network service to gain foothold access, subsequently harvesting FTP credentials and control over Google Apps‑hosted email accounts. With those credentials they replaced legitimate installers for Audacity and Classic Shell with modified binaries that contained a Master Boot Record hijacking payload. The malware rewrote the MBR on infected machines, causing a prank message to appear upon reboot while leaving the system recoverable, a technique that demonstrates a preference for low‑level persistence mechanisms that are reversible. No additional malware families or tooling styles are described in the referenced material.
Attribution to any state sponsor or criminal consortium is not explicitly stated in the open sources examined, and the group’s affiliations remain unspecified based on the evidence provided. The Fosshub compromise stands out as a notable campaign, notable for its combination of network service abuse, credential theft, and supply‑chain manipulation through trojanized installers. Prior to that operation the group was also linked to the takeover of high‑profile social media accounts, including those of Ringo Starr and the National Football League, indicating a pattern of leveraging compromised credentials for publicity‑driven actions. These incidents together illustrate the group’s recurrent use of credential‑based initial access and its willingness to affect both software distribution channels and social media platforms.
Incidents
Attributed incidents are available to members.
1 incident