CSIDB logo
Threat actor

ProjectDump

Attribution profile

Type
Criminal
Location
China
Known incidents
2 incidents
First seen
2015-12-14
Last seen
2023-01-01
Updated
2026-07-30 22:37
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

ProjectDump is an alias used by a threat actor that has been publicly associated with activity originating from China. The actor first came to attention in December 2015 when it compromised the website bluebooktrader.com. During that intrusion, the actor exfiltrated a database containing 6,187 usernames and their corresponding hashed passwords. The dumped credential material was subsequently posted online, making the information accessible to anyone who encountered the leak. This event remains the only publicly documented operation directly tied to the ProjectDump alias in the available sources.

The bluebooktrader.com incident involved the actor accessing the website’s user database and copying the stored usernames and password hashes. The leaked data consisted solely of credential material, with no indication that other types of information were taken. The public report did not specify how the actor initially gained entry to the site or what tools were used after access was obtained. No malware families, exploit kits, or post‑exploitation frameworks were mentioned in the disclosure. As a result, the exact technical approach employed by ProjectDump in this operation remains unspecified in the available sources.

Apart from the 2015 incident, no further campaigns or attributed operations have been linked to ProjectDump in the information provided. The actor’s known location in China is the only geographic detail that appears in the threat intelligence. Because the public record contains only a single confirmed intrusion, any broader characterization of the actor’s typical targets, strategic objectives, or affiliations would require additional evidence that is not present here. The available data therefore limits the profile to the confirmed alias, the stated location, and the documented credential dump from bluebooktrader.com. This concludes the factual summary based solely on the supplied information.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB