Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Void Balaur

Description

Void Balaur is a highly active hack-for-hire / cyber mercenary group with a wide range of known target types across the globe. Their services have been observed for sale to the public online since at least 2016. Services include the collection of private data and access to specific online email and social media services, such as Gmail, Outlook, Telegram, Yandex, Facebook, Instagram, and business emails.

AI Analysis

· 1 week ago

Executive Summary

Void Balaur is a highly active hack-for-hire group that offers cyber mercenary services to collect private data and gain access to various online platforms such as email and social media. They have been operational since at least 2016, targeting individuals and organizations globally. Their primary activities include cyber espionage and data theft, which poses significant risks to personal and organizational security.

Goals & Targeting

Void Balaur appears to target individuals and organizations across multiple sectors globally, suggesting no specific sector or country preference. Their goals primarily seem to involve financial gain through data collection and unauthorized access. They likely cater to clients seeking to gather competitive intelligence, disrupt business operations, or engage in personal or organizational espionage.

Enhanced Description

Void Balaur operates as a cyber mercenary group specializing in providing hacking services for hire. This group has been active since at least 2016 and offers a range of services, including unauthorized access to email accounts, social media platforms, and business emails. Their targets span multiple sectors and geographies, indicating a broad operational scope. The group's ability to exploit vulnerabilities and compromise sensitive data highlights their technical proficiency and adaptability. Void Balaur's activities underscore the growing threat of cyber mercenaries who offer their services to various clients, posing significant challenges to individual and organizational security. This group’s operations reflect a broader trend in cybercrime where specialized services are increasingly commoditized and sold on public forums.

Key Capabilities

  • Phishing attacks targeting social media and email platforms
  • Unauthorized access to online accounts
  • Data collection and exfiltration
  • Maintaining persistence via compromised accounts

MITRE ATT&CK Tactics

Initial Access (TA0001)
Execution (TA0002)

ATT&CK Techniques

T1057
T1064
T1572.001

Software / Tooling

Phishing Kits
Custom Malware for Persistence

Campaigns & Victims

Void Balaur has been active since at least 2016 and is known to target a wide range of victims globally. Their campaigns often involve compromising personal and business email accounts, leveraging social engineering techniques to gain access. Notable past operations include the compromise of numerous accounts across various platforms. The group's persistent activity suggests a high level of organizational resilience and adaptability in their operations.

IOC Patterns

  • Spear-phishing emails targeting personal and business accounts
  • Unusual login attempts from unfamiliar locations or devices
  • Presence of unauthorized access tools in target networks

Recommended Actions

  • Implement multi-factor authentication (MFA) for all critical accounts
  • Conduct regular employee training to recognize phishing attempts
  • Monitor network traffic for signs of unauthorized access or data exfiltration
  • Deploy endpoint detection and response (EDR) solutions to identify malicious activity

Suggested Tags

APT
Cyber Espionage
Hack-for-hire
Financial Motivations

Confidence Assessment

Confidence in the information about Void Balaur is medium, as details are limited but there is sufficient public reporting to establish their operational nature and goals. Key gaps include specific campaign details, exact targeting patterns, and precise toolset usage.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Cyber Espionage
Hack-for-hire
Financial Motivations

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.