Hunter butt
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Hunter butt is a pseudonym used by an individual or group identified as operating from Pakistan, known for conducting a website defacement campaign against Thai Airways in April 2018. The actor’s alias appears in public reporting as the sole identifier linked to this incident, and no additional aliases or organizational affiliations have been disclosed in the available sources. The geographic origin is explicitly noted as Pakistan, providing the only concrete location attribute for the threat actor. No further background, such as membership in a larger collective or state sponsorship, is documented in the referenced material. The actor’s activity to date is limited to the reported defacement, with no evidence of sustained operations or multiple campaigns presented in the sources.
On 23 April 2018, the actor defaced twenty‑three subdomains of the Thai Airways website, replacing their index.html files with a page that displayed an animated emoji holding a Pakistani flag. The compromised subdomains included smtp.thaiairways.com, www.thaishop.thaiairways.com, webmail.thaiairways.com, devsip.thaiairways.com, www.book.thaiairways.com, devmyidtravel.thaiairways.com, ww.thaiairways.com, mobile.thaiairways.com, tgmdmcs.thaiairways.com, epayment.thaiairways.com, devtgmail.thaiairways.com, smpbkk06.thaiairways.com, smpbkk04.thaiairways.com, smpbkk05.thaiairways.com, smpbkk03.thaiairways.com, ns.thaiairways.com, thaispaces.thaiairways.com, login.thaiairways.com, imap.thaiairways.com, how2.thaiairways.com, mail.thaiairways.com, thaisphere.thaispace.thaiairways.com, and ns1.thaiairways.com. These subdomains corresponded to critical airline systems such as the SMTP mail server, DNS nameservers, payment platforms, booking services, and various development and administrative interfaces. The defacement was accompanied by an archived copy of the altered pages posted to the Zone‑H defacement archive, a common repository for such incidents. Following the attack, Thai Airways restored its website and removed the unauthorized content, returning the affected subdomains to their original state. No malware families, specific initial access vectors, or tooling details are described in the source, limiting the technical profile to the observed defacement tactic. The incident remains the sole publicly documented operation attributed to the Hunter butt alias.
Incidents
Attributed incidents are available to members.
1 incident