Also known as: APT28, Pawn Storm, Fancy Bear, Sednit
CiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums. They have also compromised El Salvador's state Bitcoin wallet, Chivo, leaking its source code and VPN credentials. The group aims to obscure their involvement by associating with the Guacamaya group and its proxies.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CiberInteligenciaSV is a threat actor that has compromised sensitive data in El Salvador, including 5.1 million citizen records and the state Bitcoin wallet, Chivo. They have been linked to the leakage of sensitive information on Breach Forums and have attempted to obscure their involvement by associating with other groups. Their motivations and sophistication level are currently unknown, but their actions suggest a significant threat to El Salvador's digital infrastructure.
Goals & Targeting
CiberInteligenciaSV's strategic objectives and targeting profile are not well understood, but their actions suggest a focus on compromising and leaking sensitive information related to El Salvador. They may be targeting the government, financial institutions, or other organizations in an attempt to disrupt the country's digital infrastructure or gain financial benefits. Their typical victims appear to be El Salvador's citizens and government agencies, and their actions could have severe consequences for the country's economy and security.
Enhanced Description
Further research is needed to understand CiberInteligenciaSV's motivations, sophistication level, and TTPs. However, their actions demonstrate a significant threat to El Salvador's digital infrastructure, and their use of tactics like associating with other groups to obscure their involvement highlights the need for continued vigilance and monitoring of threat actor activity.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CiberInteligenciaSV's campaign patterns and operational tempo are not well understood, but their actions suggest a focus on compromising and leaking sensitive information related to El Salvador. They may be operating in a relatively short-term campaign, given the limited amount of information available about their activities. Notable past operations include the leakage of 5.1 million Salvadoran records on Breach Forums and the compromise of the state Bitcoin wallet, Chivo.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate, as there is limited information about CiberInteligenciaSV's motivations, sophistication level, and TTPs. However, their actions demonstrate a significant threat to El Salvador's digital infrastructure, and further research is needed to understand their capabilities and intentions. Information gaps exist regarding their true identities, motivations, and relationships with other threat actors.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
0
Techniques
40
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics