CSIDB logo
Threat actor

NN Hacking Group

Attribution profile

Type
Criminal
Location
Russia
Known incidents
1 incident
First seen
2016-06-01
Last seen
2016-06-01
Updated
2026-07-31 03:52
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as the NN Hacking Group is identified by its alias and has been associated with operations originating from Russia. Public reporting links the group to a specific intrusion discovered in mid‑2016. The actor’s name appears in sources describing the compromise of a payment technology provider. The group first came to analyst attention following the 2016 Verifone incident.

In that incident the NN Hacking Group focused on the payment solutions sector, specifically targeting a customer support unit that handled services for gas station fuel terminals. The attackers used phishing emails containing malicious macros to gain an initial foothold inside the corporate network. Their goal was to reach point‑of‑sale systems associated with the fuel station infrastructure. The intrusion persisted for several months before detection.

Once inside, the actors looked to exploit known weaknesses in the terminal hardware, noting that many fuel station devices had delayed upgrades to chip‑based card readers. This exploitation mirrors tactics seen in earlier attacks on other payment providers such as the Oracle MICROS breach. No mention of specific malware families or custom tooling appears in the available reports.

Attribution details beyond the geographic clue are limited; the sources do not tie the NN Hacking Group to a state sponsor or a known criminal consortium. The only publicly stated location element is the reference to Russia as the group’s base of operations.

The Verifone breach remains the most clearly documented operation attributed to the NN Hacking Group, illustrating a pattern of targeting payment infrastructure through social engineering and unpatched hardware vulnerabilities. No other campaigns are explicitly linked to the alias in the provided material.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB