CSIDB logo
Threat actor

Red Hell Sofyan

Attribution profile

Type
Activist
Location
Brazil
Known incidents
3 incidents
Sources
1 source
First seen
2016-06-20
Last seen
2021-03-08
Updated
2026-08-01 06:51
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Red Hell Sofyan and LORDBR are the primary aliases associated with this threat actor, with the contextual note that the actor’s location is listed as Brazil if known. The alias Red Hell Sofyan appears in a 2016 incident as an Algerian hacker who participated in the defacement of multiple websites belonging to the Brazilian telecommunications company Oi, while the alias LORDBR is referenced in connection with an unconfirmed allegation of involvement in a 2021 cyberattack against China’s Cosco Shipping. Public reporting does not establish a clear state sponsor or criminal consortium for the actor, and no definitive affiliations have been attributed beyond the individual hacker handles observed in the defacement case.

The actor’s observed activities include website defacement with politically motivated messages and alleged use of ransomware in separate incidents, indicating a focus on disruption and possibly financial gain. In the Oi telecom case, the attackers replaced content on fifteen web properties, including the main domain and subdomains for speed tests, offers, tutorials, and user portals, with pro‑Palestine statements, demonstrating a disruption objective without confirmed data theft. The SEPE incident in Spain involved Ryuk ransomware that encrypted files and rendered the agency’s website inoperable, forcing a suspension of services, although the origin of that attack remained unidentified during the initial response and cannot be directly tied to the actor. The alleged Cosco Shipping attack, attributed to LORDBR in some reports, remains unconfirmed and lacks publicly disclosed operational details or intrusion specifics, so any inference about its nature is speculative.

Notable TTPs referenced in the sources are limited to web defacement as the primary technique observed in the Oi telecom breach, with no disclosed initial access vector, exploit, or malware family described for that event. The SEPE case mentions Ryuk ransomware as the payload employed, but the reporting does not link the actor to its deployment or provide details on how the ransomware was introduced. Consequently, the actor’s tooling style appears to involve opportunistic web‑site alteration and, in separate reporting, potential association with ransomware campaigns, though the latter lacks substantiation. Representative operations highlighted by the available material are the 2016 mass defacement of Oi telecom’s online properties and the 2021 allegation linking LORDBR to the Cosco Shipping incident, while the SEPE Ryuk attack serves as a contextual example of ransomware activity occurring in the same timeframe but without confirmed attribution to the actor.

Incidents

Attributed incidents are available to members.

3 incidents

Sources

Sources available to members: 1 source.

CSIDB