Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CiberInteligenciaSV

CiberInteligenciaSV

TLP:CLEAR
Active

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit

Description

CiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums. They have also compromised El Salvador's state Bitcoin wallet, Chivo, leaking its source code and VPN credentials. The group aims to obscure their involvement by associating with the Guacamaya group and its proxies.

Goals & Targeting

Targeted Sectors

Healthcare
Financial services
Critical infrastructure
Defense
Government

Targeted Countries / Regions

BR
CN

AI Analysis

· 2 months ago

Executive Summary

CiberInteligenciaSV is a threat actor that has compromised sensitive data in El Salvador, including 5.1 million citizen records and the state Bitcoin wallet, Chivo. They have been linked to the leakage of sensitive information on Breach Forums and have attempted to obscure their involvement by associating with other groups. Their motivations and sophistication level are currently unknown, but their actions suggest a significant threat to El Salvador's digital infrastructure.

Goals & Targeting

CiberInteligenciaSV's strategic objectives and targeting profile are not well understood, but their actions suggest a focus on compromising and leaking sensitive information related to El Salvador. They may be targeting the government, financial institutions, or other organizations in an attempt to disrupt the country's digital infrastructure or gain financial benefits. Their typical victims appear to be El Salvador's citizens and government agencies, and their actions could have severe consequences for the country's economy and security.

Enhanced Description

Further research is needed to understand CiberInteligenciaSV's motivations, sophistication level, and TTPs. However, their actions demonstrate a significant threat to El Salvador's digital infrastructure, and their use of tactics like associating with other groups to obscure their involvement highlights the need for continued vigilance and monitoring of threat actor activity.

Key Capabilities

  • Data exfiltration
  • Credential harvesting
  • Source code leakage
  • VPN credential compromise
  • Social engineering
  • Open-source intelligence gathering

MITRE ATT&CK Tactics

Credential Access
Data Collection
Exfiltration
Initial Access

ATT&CK Techniques

T1589.001
T1059.003
T1055
T1566.001

Software / Tooling

Custom tools
Open-source tools

Campaigns & Victims

CiberInteligenciaSV's campaign patterns and operational tempo are not well understood, but their actions suggest a focus on compromising and leaking sensitive information related to El Salvador. They may be operating in a relatively short-term campaign, given the limited amount of information available about their activities. Notable past operations include the leakage of 5.1 million Salvadoran records on Breach Forums and the compromise of the state Bitcoin wallet, Chivo.

IOC Patterns

  • Data leakage on Breach Forums
  • Compromise of government systems
  • Use of custom tools
  • Social engineering tactics

Recommended Actions

  • Monitor for suspicious activity on government systems
  • Implement robust incident response planning
  • Conduct regular security audits and vulnerability assessments
  • Enhance cybersecurity awareness and training for government employees
  • Track threat actor activity on Breach Forums and other platforms

Suggested Tags

Data leakage
Government targeting
Custom tools
Social engineering
El Salvador

Confidence Assessment

The confidence level in the available data is moderate, as there is limited information about CiberInteligenciaSV's motivations, sophistication level, and TTPs. However, their actions demonstrate a significant threat to El Salvador's digital infrastructure, and further research is needed to understand their capabilities and intentions. Information gaps exist regarding their true identities, motivations, and relationships with other threat actors.

Intel Summary

0

Techniques

40

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Data leakage
Government targeting
Custom tools
Social engineering
El Salvador

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.