CSIDB logo
Threat actor

United Kingdom

Attribution profile

Type
Nation State
Location
United Kingdom
Known incidents
2 incidents
First seen
2020-05-01
Last seen
2022-12-27
Updated
2026-07-30 22:44
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is publicly referenced under the alias “United Kingdom” and is associated with the United Kingdom as its known location. Open‑source reporting links the actor to UK law‑enforcement entities, notably the National Crime Agency, which declined to comment on the operations described in the sources. The actor’s activity has been observed in two distinct incidents that illustrate a pattern of targeting both criminal communications infrastructure and a political party’s online presence.

In the Encrochat compromise, the actor deployed malware designed to evade detection, disable factory reset functions, record screen‑lock passwords, and clone application data on compromised devices. This operation was described by a source controlling an Encrochat‑associated email address as a foreign effort that appeared to originate in the UK, and it resulted in the permanent shutdown of the encrypted phone service after law‑enforcement agencies accessed user data and facilitated arrests across Europe. The PVV website attack, meanwhile, caused extended downtime and intermittent access for users of the Dutch political party’s site, with party leader Geert Wilders characterizing the assault as a “massive” effort routed through several countries including the United Kingdom; the service was restored several hours after the initial disruption.

The actor’s tactics, techniques, and procedures include the use of custom malware that conceals its presence, undermines device security mechanisms, and exfiltrates sensitive data such as lock‑screen credentials and application information. Initial access appears to have been achieved through a trusted update channel for Encrochat’s X2 models, after which a subsequent attack wave prompted the actor to issue warnings advising users to discard their devices. No additional malware families, exploit kits, or infrastructure details are disclosed in the provided material.

Notable publicly reported operations linked to this actor are the 2020 Encrochat infiltration that led to the service’s shutdown and the 2022 disruption of the PVV website. These examples demonstrate the actor’s capability to conduct both prolonged surveillance‑focused campaigns against criminal networks and shorter‑duration disruption actions targeting political entities. The actor’s known activity remains confined to the incidents described, with no further publicly attributed operations detailed in the sources.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB