Also known as: Synaptics worm, CVE-2023-34362, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
Nam3L3ss has gained notoriety by infiltrating third-party vendors and stealing sensitive corporate information from major companies, including tech giants like Amazon. This threat actor is actively selling stolen data on underground forums such as BreachForums, demonstrating a focus on financial gain through data exploitation. The targeting of service providers suggests that Nam3L3ss likely exploits vendor ecosystems to access their clients' data. Despite their operational activity, there is limited public information about their specific attack methods or tools, making them an intriguing yet elusive actor in the cybersecurity landscape.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Nam3L3ss is a multi‑sector threat actor that recently capitalized on the CVE‑2023‑34362 vulnerability in Progress Software’s MOVEit file transfer application, enabling widespread data exfiltration and extortion against thousands of organizations worldwide. The actors monetise stolen personal and corporate data by threatening to publish it or by deploying ransomware such as Clop, while simultaneously offering access to the compromised repositories on underground forums. Their activities reflect a supply‑chain focused strategy that leverages third‑party vendor ecosystems to reach critical enterprise assets across government, defense, finance, energy, and many other sectors.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
40
Tools
0
Campaigns
34
IOCs
0
Observed Data
1
Tactics