Ulzr1z
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases @ulzr1z and Ulzr1z has been publicly associated with a series of hacktivist‑style incidents originating from the United States of America, where the individual or group maintains an online presence on Twitter under the handle @ulzr1z. Observed activity began in early 2015 with claims of compromising web properties and publishing credentials, and the actor has consistently used social media platforms to announce successes and share proof of access. The actor’s public statements frequently reference the operation #OpAaronSwartz, linking the actions to commemorative efforts surrounding the death of internet activist Aaron Swartz.
Targeting has focused on educational institutions and international organizations, as demonstrated by the defacement of Massachusetts Institute of Technology course websites and the alleged breach of a United Nations subdomain. The MIT incident involved unauthorized access to the WordPress administrative console that governed fifteen subdomains, allowing the actor to replace homepages with a message that included the hacker’s handle, a Twitter reference, and the #OpAaronSwartz hashtag. In the UN case, the actor claimed to have extracted approximately 1,200 username and password pairs from sustainabledevelopment.un.org and disseminated the data via a public tweet. The actor’s tooling, as evidenced by these reports, consists of exploiting web‑application administration interfaces and leveraging paste‑bin services and Twitter for proof‑of‑concept distribution, without any publicly disclosed use of custom malware or exploit kits.
The January 2, 2015 tweet claiming the UN credential dump and the January 3, 2015 MIT defacement represent the two most thoroughly documented operations attributed to this actor. Both actions were accompanied by screenshots or links posted to Twitter and Pastebin, providing verifiable evidence of the claimed access. The MIT defacement specifically altered the homepages of fifteen course sites, including those under the Media Lab faculty, and disrupted academic resources for students while highlighting the actor’s ability to maintain persistent control over a WordPress multisite installation. These incidents illustrate a pattern of using web‑site defacement and credential disclosure as a means to convey a hacktivist message tied to the OpAaronSwartz campaign.
Incidents
Attributed incidents are available to members.
2 incidents