ManiAc Naiem
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the alias ManiAc Naiem. Open‑source reports associate this alias with Iran. Beyond the alias and location, no further personal or organizational details have been publicly disclosed.
On 2014‑10‑02 the actor claimed responsibility for a breach of the website 5‑cont.com. The claim was made in a public statement that described the site as compromised. The actor stated that they had extracted data from the site’s user database.
The disclosed dump comprised approximately twenty‑one thousand email addresses. Each email entry was paired with its corresponding password in cleartext form. Storing credentials in plaintext eliminates the need for decryption by recipients of the leak. The volume and format of the leak suggest a straightforward export rather than a sophisticated obfuscation effort.
The announcement was disseminated via a tweet from the account @maniac_naiem. The tweet included a URL linking to the location where the dump could be accessed. The tweet’s timestamp matches the date of the reported incident. No additional commentary or instructions accompanied the tweet in the publicly available record.
No other campaigns, tools, malware families, or affiliations have been attributed to ManiAc Naiem in open sources. Consequently, the actor’s typical targets, geographic focus, or strategic objectives remain undocumented. The 2014 compromise of 5‑cont.com stands as the sole publicly verified operation linked to this alias. This profile therefore reflects only the confirmed facts without extrapolation or speculation.
Incidents
Attributed incidents are available to members.
1 incident