Apophis Squad
Attribution profile
- Type
- Criminal
- Location
- Russia
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2018-06-27
- Last seen
- 2018-06-27
- Updated
- 2026-08-01 00:51
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Apophis Squad is a threat actor known by that alias and has been associated with operations originating from Russia, although the group itself has denied any Russian affiliation in private communications. The actor first came to public attention through claims of responsibility for a distributed denial‑of‑service campaign against the encrypted email provider ProtonMail in mid‑2018. Public reporting identifies the group as the self‑proclaimed source of the attack and notes that they later advertised a DDoS booter service under development. No further aliases or alternative names have been documented in the available sources.
The group’s observed targets are limited to providers of secure communication services, specifically ProtonMail and the briefly mentioned Tutanota, indicating a focus on the encrypted messaging sector. Their actions appear driven by retaliation rather than financial gain, as they launched the prolonged DDoS after ProtonMail’s chief technology officer publicly labeled them “clowns” on social media. The stated objective in the reported incident was to disrupt service availability and to demonstrate capability, which aligns with a disruption‑oriented motive. No evidence points to espionage, data theft, or profit‑making activities in the disclosed material.
Technically, Apophis Squad relies exclusively on volumetric and protocol‑level DDoS techniques, employing a mix of UDP reflection attacks, TCP bursts, and SYN floods to generate high‑bandwidth traffic. The multi‑vector nature of their assaults was highlighted by the mitigation provider Radware, which observed peaks of 500 Gbps during the ProtonMail episode and a subsequent TCP‑SYN flood reaching 70 Gbps. In addition to launching attacks, the group advertised a booter service capable of leveraging numerous reflection and amplification vectors such as NTP, DNS, SSDP, Memcached, LDAP, HTTP, CloudFlare bypass, VSE, ARME, Torshammer, and XML‑RPC. This advertising suggests a tooling style centered on readily available amplification protocols rather than custom malware or intrusion tools.
The most documented operation occurred on June 27 2018, when a sustained DDoS campaign against ProtonMail caused intermittent outages lasting from a few minutes up to approximately ten minutes, with the overall attack persisting for several hours. During the same timeframe the group briefly targeted Tutanota, though details of that engagement are scarce. The initial attack was reported to have knocked ProtonMail offline for about sixty seconds, followed by a later TCP‑SYN flood that peaked at 70 Gbps. Apophis Squad claimed responsibility for these events and framed them as a response to perceived insults, completing the publicly known narrative of their activity.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.