n0
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias n0 has also been observed using the identifier uid0 in public reports. This alias appeared in connection with a credential theft operation disclosed in mid‑2016. No additional aliases or alternative names have been publicly attributed to this actor in the available sources. The actor’s true identity remains undisclosed.
The actor’s activity focused on online community platforms, specifically targeting forums such as Mac Forums, Web Hosting Talk and HotScripts. These sites share a common parent company, which was the point of compromise used to obtain the user data. The stolen material consisted of email addresses and passwords that had been protected with salted MD5 hashes. By attempting to sell the acquired database on the dark‑web marketplace The Real Deal for 7.2 bitcoin, the actor demonstrated a financially oriented objective.
The initial access vector involved breaching the parent company’s infrastructure, although the specific technique or vulnerability was not detailed in the reports. Once inside, the actor extracted the user credential tables, which relied on MD5—a hashing algorithm considered weak and susceptible to rapid cracking. Analysts noted that roughly sixty percent of the hashed passwords could be recovered within hours due to the algorithm’s susceptibility. No particular malware families, custom tools, or exploit kits were mentioned in the public coverage of this incident.
The July 4 2016 credential theft represents the only publicly reported operation linked to the n0/uid0 alias. The breach affected approximately 1.4 million users across the affiliated forums, highlighting risks of credential reuse. Attribution to any state sponsor, criminal consortium, or organized group has not been established in the available sources. Consequently, the actor’s affiliations and broader campaign history remain unknown based on current information.
Incidents
Attributed incidents are available to members.
1 incident