Menu
Browse

ALTDOS

Primary URL Location Industry
Undetermined
Country
Financial Services Icon
Financial Services
Profile

ALTDOS is an alias used by a cybercriminal group that has been observed carrying out data‑theft and extortion operations. The group’s activity came to public attention following an attack on a Thai securities trading firm on 4 December 2020. In that incident the attackers gained unauthorized access to the firm’s network and exfiltrated a large volume of sensitive financial, customer and employee data. The stolen data included unencrypted credentials, which heightened the potential impact of the breach. After the intrusion ALTDOS issued a ransom demand of 170 bitcoin and threatened to release the stolen information if payment was not made.

The attackers employed a double‑extortion model, combining encryption‑style ransom pressure with the threat of public data leakage. When the victim firm did not meet the demand and blocked communication channels, ALTDOS followed through on its threat by publishing portions of the compromised data on public file‑sharing platforms. The group explicitly cited the victim’s inadequate security controls, such as failure to detect logins from suspicious IP addresses and the storage of critical information without encryption, as justification for the attack. By highlighting these weaknesses ALTDOS sought to pressure other organisations into improving their defenses while simultaneously demonstrating the success of its own tactics. The choice of a financial institution in Thailand suggests the group targets entities that hold valuable monetary and personal data, though no broader geographic pattern is stated in the available source.

ALTDOS’s distinguishing characteristic is its focus on stealing data before or alongside any encryption, using the stolen material as leverage for extortion. The group’s preference for ransom payments in bitcoin reflects a common practice among cybercriminals seeking pseudonymous, cross‑border transactions. Publicly leaking proof of breach serves both as validation of the attack and as a reputational weapon against the victim. No information about the group’s size, organisational structure, ownership, or parent‑subsidiary relationships is disclosed in the source material. Consequently, the profile of ALTDOS is limited to the observed tactics, techniques and procedures demonstrated in the December 2020 incident.

Incidents
Linked incidents available to members
1 incident