Menu
Browse

Cyber Threat Actor: Bloodsec International

Aliases 2 aliases
Actor Type Location Known Incidents
 Icon
Activist
Philippines
1 incident
Profile

Bloodsec International, also referred to as Blood Security Hackers International, is a threat actor that has been publicly identified operating from the Philippines. The group first came to attention in early 2015 when it compromised a journalist’s website to deliver a pointed message to then‑President Benigno Aquino III. In that incident the actors accused the president of disrespecting the memory of 44 fallen Philippine National Police‑Special Action Force officers and of arriving late to their necrological service. The hijacked site was used to post a threatening statement that called for respect and justice, and the action prompted widespread online discussion under hashtags such as #NasaanAngPangulo and #LateAngPangulo. The journalist, Alan Robles, acknowledged the breach on his Twitter account, expressing surprise that his satirical site Hotmanila.ph had attracted such attention. His wife, Raissa Robles, noted that the intrusion followed his posting of questions about the Mamasapano clash.

Besides the media outlet, the same actors have claimed responsibility for defacing a telecommunications website, again demanding accountability for the Mamasapano incident. These actions indicate a focus on political and social issues rather than financial gain or espionage. The observed tactics involve gaining unauthorized access to web servers and altering the displayed content to broadcast a political message, which is consistent with website defacement as the primary technique. No specific malware families, exploit kits, or advanced tooling have been described in the available reporting, suggesting that the group relies on relatively straightforward web‑application attacks. Public attribution does not link the actor to any state sponsor or criminal consortium; the activities are presented as independent hacktivist efforts. The two publicly reported operations—the takeover of a news site and the telecom defacement—represent the group’s known campaign pattern of using web‑site disruption to press for governmental accountability. No further details about subsequent operations, internal structure, or financial motives are available in the source material.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
1 source