CSIDB logo
Threat actor

DESORDEN

Attribution profile

Type
Criminal
Location
China
Known incidents
11 incidents
First seen
2015-04-23
Last seen
2022-10-02
Updated
2026-07-31 18:31
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

DESORDEN is a cyber threat actor known by the alias DESORDEN and has been publicly linked to operations originating from China. The group primarily targets organizations across Southeast Asia, including Thailand, Indonesia, and Malaysia, and has expressed interest in expanding to South Korea, Taiwan, Vietnam, and Japan. Their victims span multiple sectors such as insurance software vendors, toll road operators, restaurant chains, retail distributors, property firms, auction houses, and various corporate entities. DESORDEN explicitly states a financial motive, noting that stolen data can be sold for profit and that they aim to monetize breached information through direct sales or leaks on hacking forums.

In terms of tactics, DESORDEN frequently exploits unpatched vulnerabilities to gain initial access, sometimes leveraging stolen credentials, and has described breaching mainframe servers by first compromising other systems on the same network to bypass firewalls and antivirus controls. They often delete databases from compromised servers as proof of intrusion while claiming victims retain backups, and they provide proof‑of‑concept samples such as CSV files, screenshots, and recordings on hacking forums. The group has also distributed ransomware builders but asserted that these tools are ineffective against systems with basic antivirus protection and that they submit their own malware to VirusTotal to increase detection rates. DESORDEN has not been formally tied to any state sponsor or criminal consortium; their public attribution rests solely on the observed location and the pattern of their self‑reported attacks. Representative operations include the 2022 breach of The Icon Group in Thailand, which yielded 161 GB of customer and corporate data, the intrusion into PT CARE TECHNOLOGIES in Indonesia where 2.2 GB of insurance‑software databases were exfiltrated, and the compromise of a major Indonesian toll‑road operator that resulted in the theft of 252 GB of internal corporate and employee information. These incidents illustrate the actor’s focus on data theft for financial gain across the ASEAN region.

Incidents

Attributed incidents are available to members.

11 incidents
CSIDB