CSIDB logo
Threat actor

sedut

Attribution profile

Type
Criminal
Location
India
Known incidents
1 incident
First seen
2022-11-24
Last seen
2022-11-24
Updated
2026-08-01 01:24
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias sedut has been observed operating from India. sedut primarily targets organizations in the cybersecurity sector, as evidenced by the compromise of an Indian cybersecurity firm. The actor's strategic objective appears to be financial gain, demonstrated by attempts to sell stolen assets on underground forums. Initial access was achieved through the installation of Vidar Stealer malware during third‑party laptop servicing of an employee device. The malware harvested session cookies, allowing the actor to bypass multi‑factor authentication on a Jira account. With the stolen credentials, sedut gained entry to the victim’s Confluence wiki and associated Jira tickets. The actor then exfiltrated internal documents, training materials, screenshots of product dashboards, and purchase‑order information for three customers. No databases, customer login credentials, or critical systems were reported as compromised in the incident.

Following the breach, sedut posted on multiple hacking forums offering alleged access to CloudSEK’s networks, Xvigil platform, codebase, email, Jira and social media accounts for sale. The actor also leaked images containing usernames and passwords used to scrape Breached and XSS hacking forums, instructions for website crawlers, and screenshots of CloudSEK’s database schema, dashboard and purchase orders. Asking prices included approximately ten thousand dollars for the purported database and eight thousand dollars each for the codebase and internal product documentation. CloudSEK’s leadership stated that all leaked material could be traced back to specific Jira tickets and Confluence pages, confirming the source of the data. The company publicly suggested that another cybersecurity firm known for dark‑web monitoring might be behind the attack, though no definitive attribution has been established. After the incident, CloudSEK revised its access controls, conducted vulnerability assessments of the affected platforms and implemented additional security measures to prevent similar credential‑theft attacks.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB