cybervor
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases cybervor and cyberv0r has been linked to activity originating from China, according to the limited public information available. These aliases appear in multiple incident reports spanning from 2015 to 2016, suggesting a consistent online presence during that period. No further personal details or organizational affiliations have been disclosed in the sources consulted.
In July 2015 the actor claimed responsibility for compromising Miami University, stating that they had obtained and released more than two hundred usernames along with their associated password hashes. This claim was made publicly under the handle @cyberv0r and represents one of the few explicit admissions of wrongdoing attributed to the pair of aliases. In March 2016 a domain named allosambre.com was identified by Constella Intelligence’s monitoring systems as part of a large‑scale data breach that exposed identity records from a repository containing billions of compromised credentials. The same actor was not directly named in that report, but the incident is listed among the attributed activities for cybervor/cyberv0r. A third incident dated July 2016 is referenced in the sources, although no descriptive summary is provided for that event.
From the documented actions the actor’s observed behavior includes the acquisition and disclosure of credential data, as well as participation in a breach that yielded personal information usable for fraud or account takeover. No specific malware families, initial access vectors, or tooling styles are mentioned in the available material, nor are any clear statements about financial gain, espionage motives, or state sponsorship. Consequently, the profile remains confined to the verified facts of the aliases, the alleged university compromise, the connection to the allosambre.com breach, and the geographic indication of China. The actor’s activities appear focused on credential theft and data exposure, but any further interpretation would exceed the evidence supplied.
Incidents
Attributed incidents are available to members.
3 incidents