CSIDB logo
Threat actor

Phishing Group X

Attribution profile

Type
Criminal
Location
Australia
Known incidents
2 incidents
Sources
0 sources
First seen
2021-05-20
Last seen
2023-01-31
Updated
2026-07-31 03:34
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Phishing Group X is an alias used for a threat actor that has been observed operating from Australia. The actor’s known activity focuses on Australian organizations, with incidents reported in the transportation and real‑estate sectors. Observed attacks have aimed to generate financial benefit, either through ransomware encryption or through fraudulent payment schemes. No public reporting links the group to a state sponsor or to a larger criminal consortium. The actor’s activity has been noted since at least 2021, indicating a persistent presence in the region. These facts constitute the current public understanding of the group's scope and intent.

In both publicly reported cases the actor gained initial access via phishing emails that delivered malicious links or attachments. The 2023 incident involved the deployment of the CryptoLocker ransomware family, which encrypted network files and disrupted dispatch, administration and booking systems at a cab company. The 2021 incident saw the actor compromise administrative systems of a property‑listing firm and then use fraudulent websites to solicit deposit payments from users seeking rental accommodation. No other malware families or tooling have been attributed to the group in the available sources. Attribution to any specific individual or organization remains unconfirmed in open‑source reporting. These observed tactics represent the group's known operational pattern.

Incidents

Attributed incidents are available to members.

2 incidents

Sources

Sources available to members: 0 sources.

CSIDB