CSIDB logo
Threat actor

security_511

Attribution profile

Type
Sensationalist
Location
North Korea
Known incidents
4 incidents
First seen
2014-02-20
Last seen
2014-10-27
Updated
2026-07-31 22:26
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias @security_511 has been linked to a series of cyber incidents that span both financial and religious sectors. According to the provided context, the actor’s location is identified as North Korea. The observed targeting includes an Israeli online gift store, where customer credit card information was compromised and later leaked, as well as multiple religious organizations such as the Church of Scotland, the Church of Cyprus, and the Lutheran Church of Australia. In the gift store case the exposed data led to fraudulent transactions and heightened identity‑theft risks, indicating a financial motive, while the religious‑organization breaches involved the theft of user names, email addresses, and both encrypted and plaintext administrator credentials, suggesting an objective of credential harvesting for potential follow‑on activity.

The actor’s tactics, as described in the sources, involve breaching websites to extract account databases and subsequently publishing the stolen credentials on public platforms such as Pastebin and social media. In the Church of Scotland incident the actor obtained 1,570 user accounts and nine administrator accounts, with the administrator passwords disclosed in clear text, some of which were notably weak (e.g., “qwer56123”). No specific malware families, exploit kits, or initial‑access vectors are mentioned in the available material; the emphasis is on direct web‑site intrusion, credential dumping, and the use of open‑source leak sites to amplify the impact. The repeated focus on weak or reused passwords highlights a reliance on exploiting poor credential hygiene rather than sophisticated zero‑day exploits.

Attribution to the actor is supported by the explicit reference to @security_511 in the Church of Scotland breach report, and the location note of North Korea is provided in the threat‑actor context. No public statements tie the actor to a state‑sponsored program or a criminal consortium, so any claim of affiliation beyond the geographic indicator would be speculative. Representative operations that illustrate the actor’s pattern include the 2014‑10‑27 Israeli gift‑store credit‑card leak and the 2014‑02‑20 Church of Scotland credential dump, both of which demonstrate a capability to move between financially motivated targets and organizations holding sensitive personal data. This profile reflects only the facts presented in the source material, without extrapolation or assumption.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB