@GOV.ETH
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias @GOV.ETH operates from Argentina and has been identified as a hacktivist group that focuses on altering the public-facing content of websites rather than stealing data or deploying malware. Their activity has been observed primarily against news outlets, government portals, and public service sites in Argentina and neighboring Uruguay, where they replace legitimate articles or images with skull graphics, political hashtags, and occasionally AI‑generated explicit pictures of officials. The group typically accompanies these changes with a manifesto or threatening message that claims access to sensitive government databases such as Argentina’s RENAPER and police systems, although no verified data exfiltration has been reported in the sources provided. Their apparent objective appears to be political disruption and the dissemination of ideological statements rather than financial gain or espionage.
In terms of tactics, the actor relies on web‑based technique explicitly mentioned in the reporting is site defacement, whereby they gain unauthorized access to a site’s content management system and modify displayed material. They have been noted to insert static images such as skulls, to overlay AI‑generated explicit photographs, and to embed textual messages that include hashtags and signatures linking to a Telegram channel. No specific malware families, exploit kits, or phishing vectors are described in the available information, and no details about tooling, automation, or post‑exploitation frameworks are provided. Consequently, the only confirmed TTP theme is the direct alteration of web content to convey a political message.
Representative operations that illustrate their pattern include the June 2025 incident in which the Argentine news site Ámbito was defaced with skull imagery and political tags, the April 2025 alteration of the San Juan Social Action Fund website that displayed a photo of President Javier Milei alongside a condemnatory slogan and a @GOV.ETH signature, and the April 2025 defacement of TV Ciudad Montevideo in Uruguay that featured AI‑generated explicit images of officials and a manifesto threatening further attacks against governmental and commercial entities. These cases demonstrate a consistent reliance on web defacement as a means to broadcast political statements and to assert claimed access to state systems, while avoiding any mention of financial motives or data theft in the publicly reported accounts.
Incidents
Attributed incidents are available to members.
4 incidents