CSIDB logo
Threat actor

hd2416

Attribution profile

Type
Hacker
Location
Viet Nam
Known incidents
1 incident
First seen
2018-02-09
Last seen
2018-02-09
Updated
2026-07-31 00:04
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the alias hd2416 and has been identified as operating from Viet Nam. This alias appeared in connection with a domain hijacking incident targeting Newtek Business Services Corp in February 2018, where the actor communicated via the email address [email protected] that is linked to Vietnamese‑language social networking profiles. The actor’s location and alias are the only personal details publicly attributed to them in the available sources. No further biographical information such as age, real name, or affiliations has been disclosed.

The actor’s known activity focuses on compromising web infrastructure services, specifically targeting a company that provides domain registration, web hosting, and related online solutions to a broad customer base. In the Newtek case the actor seized control of three core domains—webcontrolcenter.com, thesba.com, and crystaltech.com—and replaced the legitimate login portal with a live chat service, thereby disrupting customer websites and email while creating a channel that could intercept sensitive data such as passwords. The actor claimed to have previously notified Newtek about a bug in its online operations and to have received no response before proceeding with the hijack. These actions indicate an objective of service disruption and potential credential harvesting rather than any publicly stated financial or espionage goal.

Observed tactics, techniques, and procedures include exploiting a vulnerability or bug in Newtek’s online services to gain unauthorized domain control, transferring the hijacked domains to a Vietnamese registrar (inet.vn), and substituting authentication pages with a live chat interface to capture visitor interactions. The actor used the email [email protected] for communication and maintained associated Vietnamese‑language social media profiles. Additionally, the domain giakiemnew.com, which was registered through Newtek’s own Technology Services division, suggests the actor had an existing customer relationship with the victim prior to the attack. No malware families or specific tooling suites are mentioned in the reporting.

The most significant publicly reported operation attributed to hd2416 is the February 2018 domain hijacking of Newtek Business Services Corp, which affected thousands of customer websites and email services and prompted Newtek to warn users to avoid the compromised domains. This incident remains the sole campaign explicitly linked to the alias in the open‑source record, and no other operations or affiliations have been documented.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB