F0RTYS3V3N
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor referenced in the source material is a loose collective of Bangladeshi hackers who operate under several public aliases, most notably Ne0‑h4ck3r, TiGER‑M@TE and F0RTYS3V3N, with an earlier reference to an actor known as Tiger M@te who was linked to a DNS‑redirection incident. The group is explicitly identified as Bangladeshi in the reporting, and no state sponsorship or criminal‑consortium affiliation is mentioned in the open source material. Their public presence is marked by the defacement messages they leave on compromised sites, which include the tag “#Hackers r0x Lamers Sux” and a contact e‑mail address, indicating a desire for notoriety within the hacker community rather than a disclosed financial or espionage motive.
Observed activity centers on website defacement targeting prominent internet properties in Malaysia and, historically, Kenya. In the reported incident the group defaced the Google Malaysia domain (google.com.my) and associated services such as youtube.my, ns2.google.com.my and images.google.com.my, as well as the Yahoo.my portal and its subdomains. The defacement messages appeared on the compromised pages and were mirrored on zone‑h.org as proof of the intrusion. Earlier activity attributed to the same or affiliated actors includes the defacement of the Google Kenya domain in 2013, demonstrating a pattern of targeting search‑engine and web‑portal domains in Southeast Asia and Africa. The actors’ tactics, as described, involve exploiting DNS redirection or other means to gain control of DNS records or web servers, allowing them to replace legitimate content with their own messages; no specific malware families, exploit kits or intrusion vectors are detailed in the source material beyond the defacement outcome.
The group’s operational signature consists of leaving a signed defacement page that credits the individual handles Ne0‑h4ck3r, TiGER‑M@TE and F0RTYS3V3N, includes the aforementioned hashtag and provides a point of contact via e‑mail. This pattern of claiming responsibility through visible site alteration and providing a means for observers to reach them has been noted across the Malaysian and Kenyan incidents. No further details about internal structure, funding, sponsorship or broader strategic goals are supplied in the available reporting, so the profile remains limited to the observed defacement behavior, the aliases used, the Bangladeshi attribution and the specific domains that have been publicly altered.
Incidents
Attributed incidents are available to members.
5 incidents