CSIDB logo
Threat actor

Guccifer 2.0

Attribution profile

Type
Spy
Location
Russia
Known incidents
6 incidents
First seen
2016-05-01
Last seen
2016-11-06
Updated
2026-08-01 20:56
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Guccifer 2.0 is an alias used by an individual or group that claimed responsibility for a series of intrusions against U.S. political organizations during the 2016 election cycle. The threat actor is associated with Russia in the provided context, though the persona has alternatively asserted a Romanian origin and denied any ties to the Russian government, claims that analysts have found unconvincing. U.S. officials and multiple cybersecurity firms have publicly linked the activity to Russian state‑sponsored actors, specifically referencing the groups known as Fancy Bear and Cozy Brewer, and have asserted that the intrusions were intended to influence the U.S. presidential election and to sow doubt about the security of the electoral process. The actor has described itself as a lone‑wolf hacker while simultaneously acknowledging FBI pursuit and claiming to have changed locations to evade capture.

The actor’s targeting has focused on political entities within the United States, including the Democratic National Committee, the Democratic Congressional Campaign Committee, and, according to the actor’s own statements, the Clinton Foundation. The disclosed material has consistently comprised internal party documents such as opposition research on Republican candidates—particularly Donald Trump’s tax returns and financial dealings—donor lists containing names, addresses and contribution amounts, internal memos, login credentials for various services, financial spreadsheets, and archived social‑media content. The actor has repeatedly used a WordPress‑hosted website to publish the stolen files and has highlighted the acquisition of large volumes of data, often teasing additional releases. Technical analysis performed by private security firms on the malware and tradecraft employed in the Democratic National Committee breach has attributed the activity to Russian state‑sponsored groups, although no specific malware families are named in the source material.

Notable operations attributed to Guccifer 2.0 include the June 2016 leak of Democratic National Committee opposition research on Trump’s taxes, the August 2016 breach of the Democratic Congressional Campaign Committee that exposed congressional contact details, internal memos and login credentials, and the October 2016 claim of having accessed the Clinton Foundation and released spreadsheets detailing bank contributions to lawmakers. Throughout these incidents the actor has maintained a public presence via social media and the WordPress leak site, repeatedly asserting that the FBI was actively pursuing the intruder while claiming to have relocated to avoid capture. These actions, as described in the provided sources, constitute the publicly reported campaign activity of Guccifer 2.0.

Incidents

Attributed incidents are available to members.

6 incidents
CSIDB