SerHack
Attribution profile
- Type
- Criminal
- Location
- Ukraine
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2018-09-04
- Last seen
- 2018-09-04
- Updated
- 2026-07-31 05:59
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
SerHack is the alias used by a threat actor whose activity has been publicly linked to Ukraine. The actor gained notoriety in September 2018 when the official Chrome extension for the MEGA.nz file‑sharing service was compromised with malicious code that harvested usernames, passwords, session data and cryptocurrency private keys from users visiting sites such as Amazon, GitHub, MyEtherWallet and the IDEX trading platform. The stolen information was exfiltrated to a server hosted at megaopac[.]host located in Ukraine, after which Google removed the extension from the Chrome Web Store and disabled it for existing users. The incident was described as financially motivated, with the attacker seeking to obtain credentials and private keys that could be used to access victims’ accounts and cryptocurrency funds. No evidence of espionage, disruption or state sponsorship was presented in the reporting.
The actor’s tactics, techniques and procedures involved gaining unauthorized access to the MEGA.nz Chrome Web Store account, uploading a malicious version of the extension (v3.39.4) and relying on the extension’s automatic execution on targeted websites to collect data. The malicious payload was confined to the extension itself; no separate malware families or additional tooling were described in the source material. Attribution beyond the alias SerHack and the Ukrainian hosting location has not been established publicly, and no connections to specific criminal consortia or nation‑state groups were cited. The MEGA.nz extension compromise remains the sole publicly reported operation associated with SerHack, serving as a representative example of the actor’s focus on compromising legitimate browser extensions to steal financial and authentication information.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.