Kraken
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Kraken is a threat actor known by the alias Kraken, with an indicated location in Russia. The actor has been described as pro‑Kremlin in open sources, though no direct state sponsorship has been publicly confirmed. Kraken operates under a single alias and has been linked to multiple incidents involving the compromise of online services. These details form the baseline for understanding the actor’s identity and possible affiliations.
Kraken’s targeting has focused on illicit darknet marketplaces that trade in illegal substances and on academic service platforms such as MyJSTOR. The observed victims include a Finland‑hosted Tor‑based marketplace and a digital library serving scholarly users. Geographically, the actor has demonstrated the ability to affect infrastructure located in Finland while maintaining an operational base in Russia. Their strategic objectives, as stated in the hijacking of the Solaris marketplace, are driven by competitive market interests rather than political aims, seeking to absorb a rival’s user base and undermine confidence in the breached service.
The actor’s tactics, techniques and procedures consistently involve the exploitation of critical vulnerabilities in the target’s code to gain initial access. Once inside, Kraken has harvested cleartext passwords, cryptographic keys and source code repositories, enabling them to download the victim’s infrastructure. They have also manipulated the victim’s Tor service by redirecting it to their own platform and disabling the associated Bitcoin payment server to halt financial transactions. No specific malware families or custom tooling are mentioned in the available reports, with the emphasis instead on leveraging stolen credentials and keys for persistence and control.
Two representative campaigns illustrate Kraken’s activity: the January 2022 takeover of the Solaris darknet market, where the actor exploited code flaws, seized credentials and keys, redirected the Tor site and disabled Bitcoin payments, and the March 2014 unauthorized access to roughly 800 MyJSTOR accounts that exposed usernames, passwords, email addresses and academic information without financial data loss. These incidents show a pattern of targeting both illegal marketplaces and legitimate academic services for data theft and service disruption. The actor’s pro‑Kremlin stance has been noted in reporting, but no explicit link to a state entity has been established in public sources.
Incidents
Attributed incidents are available to members.
3 incidents