Menu
Browse

Cyber Threat Actor: The Armada Collective

Actor Type Location Known Incidents
 Icon
Criminal
1 incident
Profile

The Armada Collective emerged as a cybercriminal group conducting disruptive attacks for financial gain, primarily leveraging large-scale denial-of-service operations. This threat actor gained notoriety through high-impact campaigns against digital communication platforms, employing extortion tactics to monetize their activities. Their operations demonstrated a focus on infrastructure disruption rather than data theft or persistent infiltration. The group’s name remained consistent across reporting, with no additional aliases documented in publicly verifiable sources. Their modus operandi centered on combining technical disruption with psychological pressure to coerce victims into compliance.

This group explicitly targeted email service providers, as evidenced by their coordinated attacks against Neomailbox, ProtonMail, and similar secure communication platforms. Their strategic objective centered on financial extortion, demanding ransom payments in exchange for ceasing attacks. The Armada Collective employed massive volumetric DDoS attacks exceeding 100Gbps, overwhelming victim networks through sheer traffic volume rather than sophisticated exploits. Their tooling style relied on flooding targets with malicious traffic rather than deploying malware or compromising systems through vulnerabilities. The threat actor complemented these technical attacks with explicit ransom demands, creating a dual pressure of operational disruption and financial coercion.

One significant campaign occurred in November 2015 when The Armada Collective disrupted multiple email providers simultaneously. The attacks caused multi-day service outages, severely impacting business operations and user accessibility. ProtonMail experienced particularly extended downtime despite implementing mitigation measures, highlighting the attack’s intensity. Victims faced difficult choices between paying ransom or sustaining prolonged operational damage, with some services ultimately requiring specialized DDoS protection assistance to fully restore functionality. This campaign exemplified the group’s capacity to inflict tangible business consequences through blunt-force network targeting. The coordinated nature of these attacks across multiple providers demonstrated deliberate planning to maximize extortion leverage against interdependent services.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources