CSIDB logo
Threat actor

Joe Gryn

Attribution profile

Type
Criminal
Location
South Africa
Known incidents
1 incident
First seen
2024-04-01
Last seen
2024-04-01
Updated
2026-07-30 21:48
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Joe Gryn is an alias used by a threat actor whose known location is South Africa, as indicated in publicly available reporting. The actor first came to attention in early April 2024 when a financial news website was subjected to a sustained distributed denial‑of‑service campaign. The operation targeted two specific articles that examined a trading platform’s alleged connections to fraudulent investment schemes that misused the identities of prominent business figures.

The attack generated more than a billion requests, overwhelming the site’s infrastructure and focusing traffic on the targeted content. Alongside the volumetric disruption, the actor issued extortion demands, threatening to continue the DDoS barrage and to seek domain closure unless the articles were removed. The victim’s IT team succeeded in mitigating the traffic and refused to comply with the removal requests, while the trading platform denied any involvement and referenced ongoing regulatory complaints related to the reporting.

Observed tactics, techniques, and procedures from this incident include the use of large‑scale DDoS as the primary initial access and pressure mechanism, coupled with direct extortion messaging to achieve the actor’s goals. No malware families, exploit kits, or specific tooling references were disclosed in the public account, limiting the description of the actor’s technical repertoire to the volumetric attack and accompanying coercive communication.

Publicly available sources do not establish a clear state nexus, criminal consortium affiliation, or any broader attribution for Joe Gryn beyond the alias and geographic indicator. Consequently, the actor’s ties to any government sponsor or organized crime group remain undetermined based on the evidence presented. The April 2024 DDoS and extortion operation against the financial news outlet stands as the sole publicly reported campaign associated with this actor at this time.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB