CSIDB logo
Threat actor

Hunter butt

Attribution profile

Type
Activist
Location
Pakistan
Known incidents
1 incident
First seen
2018-04-23
Last seen
2018-04-23
Updated
2026-07-30 22:09
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Hunter butt is a pseudonym used by an individual or group identified as operating from Pakistan, known for conducting a website defacement campaign against Thai Airways in April 2018. The actor’s alias appears in public reporting as the sole identifier linked to this incident, and no additional aliases or organizational affiliations have been disclosed in the available sources. The geographic origin is explicitly noted as Pakistan, providing the only concrete location attribute for the threat actor. No further background, such as membership in a larger collective or state sponsorship, is documented in the referenced material. The actor’s activity to date is limited to the reported defacement, with no evidence of sustained operations or multiple campaigns presented in the sources.

On 23 April 2018, the actor defaced twenty‑three subdomains of the Thai Airways website, replacing their index.html files with a page that displayed an animated emoji holding a Pakistani flag. The compromised subdomains included smtp.thaiairways.com, www.thaishop.thaiairways.com, webmail.thaiairways.com, devsip.thaiairways.com, www.book.thaiairways.com, devmyidtravel.thaiairways.com, ww.thaiairways.com, mobile.thaiairways.com, tgmdmcs.thaiairways.com, epayment.thaiairways.com, devtgmail.thaiairways.com, smpbkk06.thaiairways.com, smpbkk04.thaiairways.com, smpbkk05.thaiairways.com, smpbkk03.thaiairways.com, ns.thaiairways.com, thaispaces.thaiairways.com, login.thaiairways.com, imap.thaiairways.com, how2.thaiairways.com, mail.thaiairways.com, thaisphere.thaispace.thaiairways.com, and ns1.thaiairways.com. These subdomains corresponded to critical airline systems such as the SMTP mail server, DNS nameservers, payment platforms, booking services, and various development and administrative interfaces. The defacement was accompanied by an archived copy of the altered pages posted to the Zone‑H defacement archive, a common repository for such incidents. Following the attack, Thai Airways restored its website and removed the unauthorized content, returning the affected subdomains to their original state. No malware families, specific initial access vectors, or tooling details are described in the source, limiting the technical profile to the observed defacement tactic. The incident remains the sole publicly documented operation attributed to the Hunter butt alias.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB