CSIDB logo
Threat actor

ZuCaNo

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
1 incident
First seen
2021-07-01
Last seen
2021-07-01
Updated
2026-07-31 03:32
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

ZuCaNo isa threat actor known by that alias and has been linked to operations originating from the United States of America. Public reporting identifies ZuCaNo as the responsible party in a 2021 cyber campaign against a water and wastewater organization in Maine. The actor’s name appears in alerts issued by U.S. government cybersecurity authorities. No alternative aliases or additional geographic bases have been disclosed in open sources. The available information limits the actor’s profile to what is observed in that single incident.

The incident demonstrates that ZuCaNo targets critical infrastructure sectors, specifically water and wastewater facilities, within the United States. The geographic focus of the known activity is the northeastern state of Maine, indicating a regional focus on U.S. utilities. The actor’s actions were intended to disrupt the operation of essential services, as evidenced by the deployment of ransomware and the exploitation of insider threats to impair both information technology and operational technology networks. No public statements attribute espionage or financial gain as the primary motive; the described outcome centers on service interruption and potential safety risks. Consequently, the strategic objective associated with ZuCaNo’s observed behavior is disruption of critical infrastructure.

In terms of tactics, techniques, and procedures, ZuCaNo employed spearphishing messages to gain initial entry into the target environment. The actor then exploited outdated infrastructure components and insecure remote access services to move laterally and reach operational technology systems. Once inside, ransomware was deployed to encrypt data and disrupt normal functions, while insider threats were leveraged to facilitate the impact. The tooling style appears to rely on readily available malware and abuse of legitimate administrative channels rather than custom‑developed exploits. No publicly disclosed affiliations with state sponsors or criminal consortia have been attributed to ZuCaNo. The Maine water and wastewater campaign remains the sole representative operation cited in open‑source reporting for this actor.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB