CSIDB logo
Threat actor

Websites Hunter

Attribution profile

Type
Activist
Location
United Arab Emirates
Known incidents
2 incidents
First seen
2016-08-31
Last seen
2016-09-22
Updated
2026-07-31 21:55
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Websites Hunter, also referenced as websites‑hunter, operates from the United Arab Emirates and has been active since at least 2016. Public reporting identifies the individual by the handle used on Twitter and Pastebin, linking the alias to a series of website compromises aimed at drawing attention to weak security practices. The actor’s stated purpose, as revealed in a profile associated with the Twitter account, is to embarrass and expose organizations that fail to adequately protect their data. This motivation frames the activity as a form of activism rather than financial gain or espionage.

The actor’s observed targets include online gaming platforms and private healthcare facilities, both located in the United Arab Emirates. In September 2016 a gaming‑focused site that provided custom content for a popular simulation game was compromised, resulting in the theft of roughly 118 000 user accounts containing personal identifiers and unsalted MD5 password hashes. A month earlier the same actor claimed responsibility for a breach of Al Zahra Private Medical Centre, where job applicant records and patient feedback entries were disclosed; the specific intrusion technique for this incident was not disclosed in the source material. These incidents demonstrate a pattern of targeting websites that store personal data, regardless of industry, with the goal of highlighting security shortcomings.

The only confirmed initial access vector attributed to Websites Hunter is SQL injection, which was used to extract data from the gaming site’s database. No malware families, custom tools, or additional exploitation methods are described in the available reports for either incident. Consequently, the actor’s tooling style appears to rely on readily available web application attacks rather than sophisticated custom payloads. The two publicly reported operations represent the most notable campaigns linked to the alias, and no further attribution to state sponsors, criminal groups, or other affiliations has been established in the open source record.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB