CSIDB logo
Threat actor

PoodleCorp

Attribution profile

Type
Sensationalist
Location
United States of America
Known incidents
14 incidents
First seen
2014-08-24
Last seen
2016-12-23
Updated
2026-07-26 00:23
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

PoodleCorp is a threat actor that operates under the alias PoodleCorp and has been publicly linked to the United States of America. The group first gained attention through a series of distributed denial‑of‑service attacks targeting major online gaming platforms and later expanded its activities to include the hijacking of prominent YouTube channels. Public reporting consistently identifies PoodleCorp as the entity claiming responsibility for these disruptions via social media posts, particularly on Twitter, where it announced attacks and set conditions for their cessation.

The actor’s primary focus has been the online gaming sector, with observed attacks on services such as Steam, Origin, Battle.net, PlayStation Network, Xbox Live, Grand Theft Auto Online, Pokémon Go, Electronic Arts’ Battlefield titles, Blizzard’s Battle.net, and League of Legends. These services attract a global user base, so the impact of the disruptions was felt by players across multiple regions. In addition to gaming infrastructure, PoodleCorp compromised YouTube channels owned by creators such as WatchMojo, Redmercy, LeafyIsHere, and Lilly Singh, renaming videos and posting defacement messages. The group’s stated objective, as expressed in its own communications, was to halt attacks only after a specific social media engagement threshold—for example, a tweet reaching a set number of retweets—was met, indicating a motive centered on disruption coupled with a desire for notoriety rather than financial gain or espionage.

Regarding tactics, techniques, and procedures, PoodleCorp relied on volumetric DDoS attacks to overwhelm network connectivity and render services unavailable, a method repeatedly cited in the incident reports. The YouTube channel takeovers appeared to involve credential compromise, likely through password reuse or similar means, allowing the actors to rename video content and post defacement notices without deploying distinct malware families. No evidence in the supplied material points to the use of specific exploit kits, custom malware, or advanced persistence mechanisms. Attribution to a state sponsor or a known criminal consortium has not been established in open sources; the group operates under its own name and has not been linked to any larger organization. Representative campaigns include the December 2016 holiday‑season DDoS effort against Steam and Origin that coincided with peak gaming traffic, the August 2016 Blizzard and League of Legends server disruptions paired with the hijacking of several YouTube channels, and the September 2016 Battle.net attack that ended only after the group’s retweet demand was satisfied. These episodes illustrate the actor’s pattern of leveraging service disruption and social media manipulation to achieve its aims.

Incidents

Attributed incidents are available to members.

14 incidents
CSIDB