mr.nsaany
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
mr.nsaany is the alias used by a threat actor whose known location is China. Public reporting ties this alias to a single intrusion that occurred on October 30 2015, when the PHP Freaks online forum was compromised. No additional aliases, affiliations, or state connections have been disclosed in open sources for this actor. The actor’s activity to date is limited to the breach of this forum, and no broader operational pattern has been documented.
During the PHP Freaks incident the actor exploited vulnerabilities present in the forum’s software to gain unauthorized access. Once inside, they executed a custom PHP script that queried the user table and extracted its contents. The stolen data included usernames, email addresses, and password hashes that had been salted and iterated multiple times. Approximately 173 000 user accounts were affected, exposing credentials that could be reused across other services if weak passwords were chosen. The actor did not alter or delete forum content; the sole observable action was the mass export of user records.
The only tactic, technique, and procedure explicitly referenced in the reporting is the use of a PHP‑based data‑dumping script leveraging known weaknesses in the forum application. No malware families, specific malware, persistence mechanisms, command‑and‑control infrastructure, or lateral movement tools have been associated with mr.nsaany in public sources. Consequently, any description of the actor’s tooling beyond the observed script would be speculative. The incident remains the sole publicly cited operation, and further attribution or activity trends cannot be determined from the available information.
Incidents
Attributed incidents are available to members.
1 incident