N33LOB33
Attribution profile
- Type
- Hacker
- Location
- Bangladesh
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2019-04-08
- Last seen
- 2019-04-08
- Updated
- 2026-07-30 19:31
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the aliases N33LOB33 and b33 and operates from Bangladesh. Public reporting identifies the individual as responsible for a series of website defacements targeting Bangladeshi state‑owned entities. The actor first came to attention in April 2019 after compromising the Bangladesh Oil, Gas and Mineral Corporation (Petrobangla) website. The actor uses the handle N33LOB33 when leaving messages on compromised sites and the alias b33 in direct communications with reporters. The actor’s messages were written in English and included a direct invitation for the victim to reach out via the supplied email address.
The actor’s observed targets are Bangladeshi government and critical‑infrastructure sectors, specifically the energy sector and a referenced military medical institution. In the Petrobangla incident the actor defaced the website, posted a message criticizing the organization’s security posture, and provided an email address for contact. The actor claimed no data was exfiltrated and offered to remediate the identified weaknesses without charge, while also stating that a bounty would be accepted if offered. The actor described the motivation for the intrusion as the perceived null security of the victim and indicated plans to target the Bangladesh armed force medical college next. No malware, exploit kits, or specific tooling were mentioned in the reporting; the activity is limited to web‑site defacement and direct email outreach.
The only publicly documented operation attributed to N33LOB33/b33 is the April 2019 defacement of the Petrobangla website, which was subsequently restored and then re‑defaced within hours. During the same episode the actor communicated with a journalist under the alias b33, confirming the lack of data theft and discussing the possibility of a bounty for the reported vulnerability. The actor also announced an intention to strike the Bangladesh armed force medical college, although no further evidence of that attack has been presented in open sources. The actor’s email address used a mail.ru domain, as shown in the defacement notice. No affiliations with state sponsors, criminal groups, or larger hacking collectives have been established in the available material. Consequently, the actor remains classified as an independent individual acting from Bangladesh.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.