Sawarim
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Sawarim has been referenced in open-source reporting. The alias Sawarim is the primary name used to track this group. Publicly available information associates the actor with Russia as its known location. No additional aliases or geographic details are provided in the source material.
The only publicly attributed activity of Sawarim involves a breach of a Hungarian educational technology provider. The targeted organization, eKRÉTA, operates a school management platform used across Hungary. The platform stores personal information of students aged six to eighteen, exceeding seven hundred thousand records. The source does not state whether the actor’s motivation is financial, espionage, or disruption-oriented. The attackers communicated to a local outlet that they do not intend to release the student personal data they accessed.
The reporting does not describe any specific malware families employed by Sawarim. No details are given regarding the initial access vectors used in the eKRÉTA compromise. Information about the group’s tooling style or preferred utilities is absent from the source. Consequently, any technical tactics, techniques, or procedures remain undocumented in the available material.
In November 2022, Sawarim disclosed that it had obtained access to eKRÉTA’s internal systems. The group subsequently began leaking portions of the company’s proprietary source code. Alongside the code, internal chat logs and email exchanges were made public, some involving correspondence with state officials. The attackers asserted that they would not publish the personal data of the students stored on the platform. This incident represents the sole publicly reported operation linked to Sawarim to date.
Incidents
Attributed incidents are available to members.
1 incident