ROR[RG]
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
ROR[RG] is a threat actor known by the alias ROR[RG] and has been associated with operations originating from Russia. The actor first came to public attention through a claim of responsibility for the Adult FriendFinder data breach, in which personal details of millions of users were allegedly exposed, and later through the leak of Turkish National Police databases. These incidents are the only activities explicitly linked to the alias in the provided sources.
The actor’s targeting appears to focus on sectors that involve sensitive personal or governmental information, specifically online adult services and national law‑enforcement agencies in Turkey. Statements made by ROR[RG] indicate that the motivation for the Turkish police leak was to expose alleged corruption, abuse of power, and excessive violence by the police force, framing the action as a response to perceived governmental misconduct rather than financial gain or espionage. No explicit mention of financial objectives, state sponsorship, or affiliation with a criminal consortium is present in the material.
Regarding tactics, the disclosed data consisted of MySQL database backup files with the extensions .myd and .myi, suggesting the actor was able to extract database dumps from the compromised systems. The actor claimed to have retained ongoing access to the hacked Turkish police servers at the time of the leak, but the sources do not detail specific malware families, initial‑access vectors, or particular tooling used to achieve this access. Consequently, only the acquisition and release of database backups can be confirmed as part of the actor’s observed behavior.
The two publicly reported operations that define ROR[RG]’s profile are the Adult FriendFinder breach, which involved the alleged compromise of a large‑scale dating platform and the exposure of user data, and the Turkish National Police leak, in which approximately 17.8 GB of MySQL backups were released via BitTorrent links. These incidents illustrate the actor’s pattern of targeting entities holding substantial personal or governmental data and releasing the material to highlight perceived wrongdoing. No additional campaigns or technical details are described in the available information.
Incidents
Attributed incidents are available to members.
4 incidents