CSIDB logo
Threat actor

B00daMooda and @DepaixPorteur.

Attribution profile

Type
Activist
Location
Ukraine
Known incidents
2 incidents
First seen
2022-03-26
Last seen
2022-05-11
Updated
2026-08-01 04:58
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the aliases B00daMooda and @DepaixPorteur operates from Ukraine and is publicly associated with the hacktivist collective Anonymous. These aliases appear together in leak announcements where the actors claim to support Ukraine in its conflict with Russia. Their affiliation with Anonymous places them within a loosely organized network of individuals conducting politically motivated cyber operations. No evidence in the provided material links them to a state sponsor or a criminal consortium.

Their activities have focused on Russian organizations across several sectors. Observed targets include government bodies, industrial firms, energy companies, and transportation infrastructure. The actors have participated in the broader OpRussia campaign, which aligns with Anonymous' stated goal of protesting the Russian invasion of Ukraine. The campaign aims to expose internal data and disrupt the target’s operations as part of a larger effort to undermine the war effort. The operation has resulted in the exfiltration of hundreds of gigabytes of correspondence from multiple Russian entities. The strategic objective evident from the leaks is to undermine the Russian war effort through information disclosure rather than financial gain or traditional espionage. No mention of profit‑driven motives appears in the sources.

Representative operations attributed to B00daMooda and @DepaixPorteur include the May 2022 leak of 466 gigabytes of internal emails from the Polar Branch of the Russian Federal Research Institute of Fisheries and Oceanography, which was shared via the DDoSecrets platform. Another example is the March 2022 breach of RostProekt, which yielded 112 gigabytes of data comprising over 140 000 emails and was distributed through torrent services. The same actors were also credited with leaking data from SOCAR Energoresource, the Achinsk city government, and the Port and Railway Projects Service of JSC UMMC as part of the same OpRussia wave, with the material likewise posted on DDoSecrets. The leaked emails were intended to reveal internal discussions and potentially embarrass the targeted organizations. The source material does not describe any specific malware families, initial‑access vectors, or tooling used by the actors, so no technical TTPs can be confirmed from the available information.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB