Mormoroth
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Mormoroth, also known by the alias Mourner, is an Iranian hacker who came to public attention in February 2014 after compromising the Network Information Center of Paraguay (nic.py). The actor operates under the online moniker Mormoroth and has been linked to a single publicly at the individual acting from any publicly available. The attack chain of remote code execution vulnerability in the nic.py breach through screenshots, a blog post on ha.cker.ir, and leaked credentials. The incident is the only publicly documented operation attributed to this alias in the provided sources.
During the nic.py intrusion Mormoroth exploited a remote code execution vulnerability to gain access to the backend systems. The actor noted that inappropriate directory permissions allowed unrestricted browsing and reading of files without needing to obtain full root control, although a localroot exploit could have been used to achieve privileged access. After gaining entry, Mormoroth altered DNS records for google.com.py to redirect visitors to a defacement page, published screenshots demonstrating the compromise, and leaked user credentials and internal data from the site’s databases. The actor also explained in a blog post that the decision to leak information followed Paraguayan authorities’ denial of any breach despite prior warnings from a cybersecurity expert about the unaddressed vulnerability.
The operation targeted a governmental internet registry in Paraguay, affecting the DNS resolution of a major local domain and resulting in the exposure of sensitive account information. No further campaigns or additional victims are described in the available material, and no explicit links to state sponsorship, criminal groups, or financial motives are presented. Consequently, the profile is limited to the confirmed facts of the 2014 nic.py breach, the associated TTPs involving vulnerability exploitation and permission misconfiguration, and the observed outcomes of defacement and data leakage.
Incidents
Attributed incidents are available to members.
1 incident