Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ALTDOS

Also known as: other aliases, Jumpy Pisces, several other aliases, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, ZINC

Description

ALTDOS, also known by aliases such as Jumpy Pisces and Desorden (0mid16B), emerged in the mid‑2010s and has focused on Southeast Asian markets, particularly Singapore, Thailand, Malaysia, and Indonesia. The organization conducts data breaches of real estate, retail, finance, healthcare, and government entities, harvesting sensitive information like customer names, bank account numbers, and transaction details. The group couples large‑scale ransomware deployments—utilizing malware families such as BlackCat (ALPHV), Ryuk, REvil/Sodinokibi, Clop, and Maze—with systematic data exfiltration. In addition to demanding ransom payments, ALTDOS publicly leaks compromised data on underground forums when demands are not met, amplifying pressure on victims. Tactics include spear‑phishing with macro‑laden Office documents, exploitation of SQL injection points for initial access, use of zero‑day exploits and custom backdoors for persistence, and command‑and‑control via encrypted HTTPS or the Matrix chat protocol. Its operational footprint demonstrates a blend of financially driven motives combined with capabilities often associated with state‑sponsored actors in the region.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Telecommunications
Critical infrastructure
Manufacturing
Media
Education
Energy
Retail
Gaming
Aerospace
Non profit
Aviation
Transportation
Think tank
Hospitality
Maritime
Legal services
Utilities

Targeted Countries / Regions

RU
US
SG
IR
CN
IN
BR
KP
KR
CA
GB
TR
UA
VN

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

ALTDOS is a financially motivated threat actor primarily targeting Southeast Asian entities across multiple sectors, deploying ransomware and exfiltrating customer data for sale or ransom. The group leverages sophisticated phishing campaigns, zero‑day exploits, and public data dumps to pressure victims into paying. Despite unclear national sponsorship, its operations mirror North Korean‑linked groups such as Andariel and Chaotic Spider.

Goals & Targeting

ALTDOS strategically targets high‑value sectors—financial services, defense, healthcare, telecommunications, critical infrastructure, and retail—to harvest and monetize sensitive data or extort through ransomware. The group’s focus on Southeast Asia is driven by perceived lower security maturity, a diverse regulatory landscape, and the region’s rapidly growing digital economy. By leaking exfiltrated data if ransom demands are unmet, ALTDOS exploits both financial incentives and reputational damage to coerce compliance, aligning with the broader modus operandi of North Korean‑affiliated groups that support regime funding and intelligence objectives.

Enhanced Description

Key Capabilities

  • Advanced ransomware delivery

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 10 Domain 9 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. www.sentinelone.com — Cited by web research for: Singularity
  3. www.group-ib.com — Cited by web research for: Matrix
  4. www.group-ib.com — Cited by web research for: UK

Intel Summary

0

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Data Exfiltration
Data Breach
Southeast Asia
Cybercrime
Espionage
Data breach
Financially motivated
APT
Data Theft
Financial Sector
Retail Sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.