CSIDB logo
Threat actor

Team Cyber Criminals

Attribution profile

Type
Sensationalist
Location
Pakistan
Known incidents
5 incidents
First seen
2014-03-18
Last seen
2025-06-01
Updated
2026-07-31 03:23
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The actor is known by the aliases Team Cyber Criminals and CyberTeam and is publicly associated with Pakistan. Their observed activity includes targeting government information portals, national assembly websites, and automotive manufacturer sites in regions such as Paraguay, Angola, Cabo Verde, and Guatemala. In the incidents described, the actors stated that intrusions were carried out “just for fun” and left boastful messages indicating a desire to show off, which points to a strategic objective of disruption and notoriety rather than financial gain or espionage.

Their tactics involve exploiting shared vulnerabilities in web applications that were developed by a common third‑party provider, allowing them to deface multiple sites with a single exploit. The defacements consist of posting messages such as “Hacked by Algeriano” and sharing links to Discord and X accounts to increase visibility. No malware families or specialized tooling are mentioned in the source material; the primary tooling style appears to be web‑site compromise for defacement and publicity. Regarding attribution, the actors have claimed affiliation with the self‑described “Exército Cibernético da Comunidade dos Países de Língua Portuguesa,” but no explicit state sponsorship or criminal consortium linkage is publicly established in the provided information.

Representative operations include the June 2025 disruption of Paraguay’s Portal Unificado de Acceso a la Información Pública, the April 2025 defacement of Angola’s National Assembly website (with claims of prior access to several Angolan governmental databases), and the March 2014 defacement of Guatemalan Chevrolet, Renault, and Toyota sites. Across these events, the actors caused temporary downtime and reputational harm, restored the affected sites within approximately 24 hours, and left no evidence of sensitive data exfiltration according to the overseeing authorities. These incidents demonstrate a pattern of targeting publicly accessible web assets for the purpose of visible disruption and self‑promotion.

Incidents

Attributed incidents are available to members.

5 incidents
CSIDB