CSIDB logo
Threat actor

Russian hackers

Attribution profile

Type
Undetermined
Location
-
Known incidents
1 incident
Sources
0 sources
First seen
2023-07-11
Last seen
2023-07-11
Updated
2026-09-14 07:29
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is publicly referenced only by the aliases “Russian hackers” and “Russian‑speaking hackers.” No definitive identity, organizational structure, or state sponsorship has been established in open sources. These labels appear in reporting that links the group to cyber incidents where language or infrastructure hints at a Russian nexus, but attribution remains unverified.

In July 2023 the actor carried out a ransom‑motivated operation against the Province de Namur in Belgium. On 2023‑07‑11 they succeeded in compromising five of the province’s servers, an action that triggered a ransom demand communicated to the victims. The demand explicitly indicated a financial objective, seeking payment in exchange for restoring access to the affected systems. As a direct consequence of the intrusion, several provincial services were disrupted, impairing normal administrative functions and raising concerns about the confidentiality of stored data. Although no confirmed data exfiltration has been disclosed, the breach potential was noted by investigators who warned that sensitive information could have been accessed during the compromise. The attackers have not been identified, and no public attribution to a specific criminal syndicate or government body has been made.

The Namur incident reveals that the actor possesses the capability to gain unauthorized access to multiple government servers and to leverage that access for extortion. While the specific initial vector, malware families, or tooling employed are not detailed in the available reporting, the presence of a ransom note demonstrates an ability to deploy or threaten disruptive payloads. No additional campaigns or tools have been publicly linked to this alias set, limiting further insight into their operational patterns. Consequently, the profile of this threat actor rests solely on the observed compromise of Belgian provincial infrastructure, the associated ransom demand, and the resulting service disruption and potential data exposure.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 0 sources.

CSIDB