Cyber Threat Actor: KuroiSH
| Actor Type | Location | Known Incidents |
Activist
|
France
|
1 incident |
|---|
Profile
The threat actor known publicly as Amar^SHG (formerly Kuroi’SH) and also referenced as Kuroi SH has been identified in multiple open‑source reports as the individual behind a series of website defacements and data disclosures. The actor uses the aliases Amar^SHG, Kuroi’SH and Kuroi SH interchangeably across different incidents and has claimed responsibility for actions against French, United States government and media targets. Reported targets include the Météo France weather portal, the French television service Canal+, the United States military usuhs.mil domain, the Kennedy Space Center NASA server and the Uniformed Services University of the Health Sciences, indicating a focus on government, military and media sectors in France and the United States. The actor has publicly stated that certain actions were motivated by anti‑war sentiments and, in the case of the Uniformed Services University breach, were carried out in support of Palestine, indicating a political rather than financial motive.
Reported tactics, techniques and procedures consistently involve the use of SQL injection to gain initial access, as demonstrated in the Météo France incident where an SQLi flaw in the registrar OXYD’s extranet was exploited to obtain control of the domain registrar and deploy a defacement page. The actor has also claimed to have accessed and defaced the Kennedy Space Center NASA server, Canal+ and the US military usuhs.mil domain, although specific technical details for those intrusions were not disclosed in the sources. In the Uniformed Services University operation, the actor uploaded defacement pages to eight university domains and exfiltrated a database containing usernames, email addresses and plain‑text passwords, which were subsequently leaked online. No specific malware families, custom tooling or exploit kits are mentioned in the available material. Public attributions to state sponsors or criminal syndicates are absent from the sources; the actor’s affiliations are limited to the self‑described political motivations cited in the interviews and statements accompanying the attacks. Representative operations cited in the reporting include the anti‑war defacement of Météo France, the claimed intrusion into NASA’s Kennedy Space Center systems, the alleged compromise of the US military usuhs.mil domain and the credential leak from the Uniformed Services University conducted in support of Palestine. These incidents collectively illustrate a pattern of politically motivated website defacement and data exposure targeting governmental and media entities in Western nations.
