Russian hackers
Attribution profile
- Type
- Undetermined
- Location
- -
- Known incidents
- 1 incident
- Sources
- 0 sources
- First seen
- 2023-07-11
- Last seen
- 2023-07-11
- Updated
- 2026-09-14 07:29
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is publicly referenced only by the aliases “Russian hackers” and “Russian‑speaking hackers.” No definitive identity, organizational structure, or state sponsorship has been established in open sources. These labels appear in reporting that links the group to cyber incidents where language or infrastructure hints at a Russian nexus, but attribution remains unverified.
In July 2023 the actor carried out a ransom‑motivated operation against the Province de Namur in Belgium. On 2023‑07‑11 they succeeded in compromising five of the province’s servers, an action that triggered a ransom demand communicated to the victims. The demand explicitly indicated a financial objective, seeking payment in exchange for restoring access to the affected systems. As a direct consequence of the intrusion, several provincial services were disrupted, impairing normal administrative functions and raising concerns about the confidentiality of stored data. Although no confirmed data exfiltration has been disclosed, the breach potential was noted by investigators who warned that sensitive information could have been accessed during the compromise. The attackers have not been identified, and no public attribution to a specific criminal syndicate or government body has been made.
The Namur incident reveals that the actor possesses the capability to gain unauthorized access to multiple government servers and to leverage that access for extortion. While the specific initial vector, malware families, or tooling employed are not detailed in the available reporting, the presence of a ransom note demonstrates an ability to deploy or threaten disruptive payloads. No additional campaigns or tools have been publicly linked to this alias set, limiting further insight into their operational patterns. Consequently, the profile of this threat actor rests solely on the observed compromise of Belgian provincial infrastructure, the associated ransom demand, and the resulting service disruption and potential data exposure.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 0 sources.