CSIDB logo
Threat actor

EvoIsGod

Attribution profile

Type
Activist
Location
Greece
Known incidents
1 incident
First seen
2016-12-24
Last seen
2016-12-24
Updated
2026-07-31 05:24
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

EvoIsGod is a threat actor known by the alias EvoIsGod and is believed to operate from Greece. The actor frequently collaborates with another individual using the handle Cryptolulz666, who has been identified as a former member of the Powerful Greek Army. This partnership has been observed in multiple public disclosures where both handles claim responsibility for intrusions. The actor’s public presence is limited to the incidents described in available reporting, with no additional personal details or organizational structure disclosed beyond the association with Cryptolulz666.

The actor’s demonstrated targeting includes media organizations and government entities, as evidenced by the breach of the Hong Kong‑based English newspaper “The Standard Hong Kong” and prior claims of attacks against the Russian embassy in Armenia, an Italian government startup visa website, and the Russian Federal Drug Control Service liquidation commission. The stated strategic objective in the Hong Kong incident was to raise cybersecurity awareness and embarrass the target by exposing perceived security flaws, rather than to pursue financial gain or espionage. No public statements indicate a motive related to profit, data monetization, or state‑directed intelligence collection.

The actor’s tactics, techniques and procedures highlighted in the reporting rely primarily on exploiting SQL injection vulnerabilities in content management systems to gain initial access to web applications. After compromising the database, the actor exfiltrated user records and elected to publish only a subset of the data on Pastebin, citing legal concerns as the reason for withholding the remainder. No specific malware families or custom tooling are mentioned in the sources, and the actor’s tooling style appears to consist of standard web‑application attack techniques combined with public data leaks. Affiliation with Cryptolulz666, who references past government‑focused operations and a background in the Powerful Greek Army, suggests a loose collaborative relationship, but no formal state nexus or criminal consortium is explicitly established in the available material. The most notable publicly reported operation remains the December 2016 intrusion of The Standard Hong Kong newspaper, which exemplifies the actor’s focus on demonstrative breaches aimed at highlighting inadequate security practices.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB