DayKalif
Attribution profile
- Type
- Hacker
- Location
- Russia
- Known incidents
- 3 incidents
- Sources
- 3 sources
- First seen
- 2011-01-01
- Last seen
- 2021-09-30
- Updated
- 2026-08-28 15:59
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases DayKalif and AnibaLeaks has been linked to a series of high‑profile data exposures that span both governmental and commercial targets. Operating from Russia, the actor first gained attention in 2011 when a database containing approximately 33 million user accounts from the Russian instant messaging service QIP.ru was provided to a cybersecurity firm; the credentials were stored in plaintext without encryption or hashing, allowing immediate use. A year later, in February 2012, the actor supplied a dump of nearly 100 million records from the Russian internet portal Rambler to a breach notification service, again revealing usernames, email addresses and passwords kept in plaintext, with weak combinations such as “123456” and “asdasd” appearing frequently. These incidents demonstrate a pattern of exploiting poorly protected credential stores in Russian online services and making the resulting data available through third‑party platforms.
In September 2021 the actor shifted focus to a government target, compromising Argentina’s National Registry of Persons (RENAPER) via a virtual private network account assigned to the Ministry of Health. The breach exposed national identification details for the entire Argentine population, and the actor subsequently offered to look up or sell the stolen information, providing samples that included celebrity records and unique identification numbers to prove possession. While officials initially denied any leakage, later confirmation acknowledged unauthorized VPN access, though they maintained that no data had been leaked; the actor’s evidence contradicted that claim. The actor’s tactics in this case centered on leveraging legitimate VPN credentials for initial access, a method distinct from the earlier exploitation of unencrypted password databases.
Across these operations the actor consistently seeks to monetize or distribute harvested personal data, advertising lookup services and offering the material for sale on underground markets. No public statements tie the actor to a specific state sponsor or organized criminal consortium, and the available sources do not describe particular malware families, custom tools, or additional intrusion techniques beyond the use of compromised VPN access and the exploitation of plaintext credential storage. The actor’s known activities therefore illustrate a recurring focus on acquiring large volumes of weakly protected user data from both Russian internet platforms and a South American government identity system, with the apparent goal of financial gain through the resale or brokerage of that information.
Incidents
Attributed incidents are available to members.
3 incidentsSources
Sources available to members: 3 sources.