Sanadodeh Nesheiwat
Attribution profile
- Type
- Criminal
- Location
- United States of America
- Known incidents
- 4 incidents
- Sources
- 1 source
- First seen
- 2011-01-01
- Last seen
- 2011-01-01
- Updated
- 2026-08-01 00:44
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Sanadodeh Nesheiwat, also known by the alias Sanadodeh Nesheiwat, is a United States‑based individual who was identified as a member of the Xbox Underground hacking ring. He was charged in April 2014 alongside three co‑defendants with multiple federal offenses related to computer fraud, copyright infringement, wire fraud, mail fraud, identity theft and theft of trade secrets. Nesheiwat pleaded guilty to conspiracy to commit computer fraud and copyright infringement, admitting his role in the conspiracy. He faced a potential maximum sentence of five years in prison and was awaiting sentencing at the time of the 2014 report. His co‑defendant David Pokora also entered a guilty plea to the same charges.
The Xbox Underground group conducted intrusions into a range of technology and defense organizations, including Epic Games, Microsoft, Valve, Zombie Studios and the United States Army. According to the Department of Justice allegations, the attackers accessed these networks between January 2011 and March 2014 using SQL injection techniques and stolen employee credentials. The compromised systems yielded unreleased software, source code, pre‑release video game titles and military training software such as Apache helicopter simulation tools. The stolen intellectual property was assessed by prosecutors to be worth between one hundred million and two hundred million dollars. No customer data was reported as taken in the breaches.
The primary initial access vectors described in the indictment were SQL injection attacks and the use of compromised username and password pairs belonging to company employees or their software development partners. No specific malware families or custom tools were referenced in the publicly available reporting. The group’s tooling style therefore appears to have relied on credential theft and web application exploitation rather than deployed malicious code. These methods enabled the actors to move laterally within the targeted networks and exfiltrate the described intellectual property.
Attribution to a broader state sponsor has not been established in the open sources; the activity is attributed to a criminal consortium known as Xbox Underground. The ring consisted of the four U.S.‑based defendants plus an additional Australian suspect who was also charged in connection with the conspiracy. The guilty pleas of Nesheiwat and Pokora marked the first admissions of guilt in the case, while the remaining defendants proceeded to trial. The case highlighted the cross‑national nature of the investigation, with U.S. prosecutors coordinating with authorities abroad.
Incidents
Attributed incidents are available to members.
4 incidentsSources
Sources available to members: 1 source.