CSIDB logo
Threat actor

Nathan Leroux

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
4 incidents
First seen
2011-01-01
Last seen
2011-01-01
Updated
2026-07-31 21:21
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Nathan Leroux, also known by his alias, is an individual associated with the hacking collective referred to as Xbox Underground. He resides in Bowie, Maryland, United States of America, and was among four individuals charged in connection with a series of intrusions that occurred from January 2011 through March 2014. The group’s activities centered on the theft of unreleased software, source code, pre‑release video game titles, and military training technology from a range of technology and defense organizations.

The collective primarily targeted technology firms such as Microsoft, Epic Games, Valve, and Zombie Studios, as well as the United States Army, indicating a focus on both corporate and military sectors within the United States. Their strategic objective, as described in the indictment and related reporting, was financial gain through the exfiltration of intellectual property valued between $100 million and $200 million, with no public indication of espionage or disruptive aims. Reported tactics, techniques, and procedures included the use of SQL injection attacks to gain initial access and the exploitation of stolen employee usernames and passwords, sometimes obtained from software development partners, to move laterally within victim networks. No specific malware families or custom tooling were referenced in the available sources.

Attribution to a state sponsor is not evident; the actors are publicly characterized as a criminal hacking ring operating under the name Xbox Underground. The most notable campaign described in the material involves the sustained intrusion into Microsoft, Epic Games, Valve, Zombie Studios, and U.S. Army systems, resulting in the theft of assets such as Apache helicopter simulation software, pre‑release copies of games like Call of Duty: Modern Warfare 3 and Gears of War 3, and associated source code. Legal proceedings led to federal charges of conspiracy to commit computer fraud, copyright infringement, wire fraud, mail fraud, identity theft, and theft of trade secrets, with two of the defendants pleading guilty to conspiracy charges and facing potential prison sentences, while an additional Australian suspect linked to the conspiracy was also charged.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB