Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Nam3L3ss

Also known as: Synaptics worm, CVE-2023-34362, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

Nam3L3ss has gained notoriety by infiltrating third-party vendors and stealing sensitive corporate information from major companies, including tech giants like Amazon. This threat actor is actively selling stolen data on underground forums such as BreachForums, demonstrating a focus on financial gain through data exploitation. The targeting of service providers suggests that Nam3L3ss likely exploits vendor ecosystems to access their clients' data. Despite their operational activity, there is limited public information about their specific attack methods or tools, making them an intriguing yet elusive actor in the cybersecurity landscape.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Aerospace
Media
Education
Manufacturing
Healthcare
Information technology
Maritime
Think tank
Pharmaceutical
Chemical
Mining
Retail
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
TW
IL
FR
CA
TR
AU
KZ
PK
VN
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Nam3L3ss is a multi‑sector threat actor that recently capitalized on the CVE‑2023‑34362 vulnerability in Progress Software’s MOVEit file transfer application, enabling widespread data exfiltration and extortion against thousands of organizations worldwide. The actors monetise stolen personal and corporate data by threatening to publish it or by deploying ransomware such as Clop, while simultaneously offering access to the compromised repositories on underground forums. Their activities reflect a supply‑chain focused strategy that leverages third‑party vendor ecosystems to reach critical enterprise assets across government, defense, finance, energy, and many other sectors.

ATT&CK Techniques

Impact
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.techtarget.com — Cited by web research for: CVE-2023-34362
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.ncsc.gov.uk — Cited by web research for: phishing
  4. flare.io — Cited by web research for: ASP.NET
  5. www.infostealers.com — Cited by web research for: fmr.com

Intel Summary

1

Techniques

40

Tools

0

Campaigns

34

IOCs

0

Observed Data

1

Tactics

Tags

Supply Chain Attack
Data Exfiltration
Data breach
Ransomware
Third-party compromise
Financial gain

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.