Group-IB Investigation Aids Arrest of ALTDOS Data-Leak Extortion Actor

Summary
Group-IB says its investigation linked an actor using aliases including ALTDOS and DESORDEN to data breaches and extortion across multiple regions. Intelligence shared with Thai and Singapore police contributed to a raid and arrest in Thailand.
Key points
- Group-IB investigated a series of data breaches beginning in 2020, linking the operator to aliases including ALTDOS, DESORDEN, GHOSTR and 0mid16B.
- The actor reportedly gained access through vulnerable RDP servers and SQL injection, then used a cracked Cobalt Strike beacon and exfiltrated databases to rented cloud servers.
- The extortion scheme involved threatening public exposure, leaking or selling stolen data, and demanding payment to keep data private.
- Group-IB says the actor’s activity expanded from Southeast Asia to the UK, US, Canada and the Middle East; reported leaks totaled 13 TB and included millions of personal records.
- Investigators correlated technical indicators, dark-web activity, account logs, database overlaps and behavioral patterns to link the aliases to one operator.
- Group-IB provided intelligence to the Royal Thai Police and Singapore Police Force; a raid in Thailand resulted in the suspect’s arrest and seizure of electronic devices.
Article Details
- Event Type
- Law-enforcement arrest and cyber-extortion takedown
- Impact
- Authorities arrested the suspect in Thailand and seized electronic devices and luxury goods reportedly purchased with illicit proceeds. Group-IB attributed breaches involving 13TB of leaked data and millions of personal records to the operator. Victims faced data theft, extortion demands, public disclosure, and sales of stolen databases. The article reports attacks on government agencies, but the Royal Thai Police separately stated that the suspect admitted targeting large private companies while avoiding government agencies.
MITRE ATT&CK
T1021.001 · Remote Desktop ProtocolGroup-IB identified unauthorized RDP access to vulnerable servers used to access sensitive data.T1190 · Exploit Public-Facing ApplicationInvestigators reported SQL injection against vulnerable servers to obtain access to internal databases.T1583.004 · ServerThe actor rented cloud servers under false identities to receive exfiltrated data.
People
Threat Actors
0mid16BAlias attributed by Group-IB to the same data-theft and extortion operator as ALTDOS, DESORDEN, and GHOSTR.ALTDOSData-theft and extortion alias attributed by Group-IB to the arrested operator, who also used DESORDEN, GHOSTR, and 0mid16B. The article describes an earlier forum appearance as mystic251.DESORDENAlias used by the same operator identified as ALTDOS, GHOSTR, and 0mid16B, according to Group-IB; offered stolen databases and samples on criminal forums.GHOSTRAlias attributed by Group-IB to the same operator as ALTDOS, DESORDEN, and 0mid16B; associated with data breaches targeting Thai victims and later international expansion.mystic251Earlier handle attributed by the article to the same operator; posted about a database from a Singapore furniture retail chain on CryptBB in April 2021.
Products
Tools
Cobalt StrikeHe would then a beacon of a cracked version of the Cobalt Strike pentesting toolkit to control compromised servers.sqlmapAnalysis revealed the use of SQL injection and tools, such as sqlmap, resulting in the exfiltration of internal databases containing personal records, contracts, and contact information.
Countries
CanadaBy 2024, he was also breaching companies in the United Kingdom, the United States, Canada, and the Middle East, under the aliases GHOSTR and 0mid16B.IndiaOver time, his targeting expanded across the Asia-Pacific region, reaching organizations in Singapore, Malaysia, Indonesia, India, and beyond.IndonesiaOver time, his targeting expanded across the Asia-Pacific region, reaching organizations in Singapore, Malaysia, Indonesia, India, and beyond.MalaysiaOver time, his targeting expanded across the Asia-Pacific region, reaching organizations in Singapore, Malaysia, Indonesia, India, and beyond.SingaporeOver time, his targeting expanded across the Asia-Pacific region, reaching organizations in Singapore, Malaysia, Indonesia, India, and beyond.ThailandHis campaigns began in 2020, with initial targets in Thailand, where he focused on exfiltrating sensitive customer data from corporations and demanding hush-money payments.United KingdomBy 2024, he was also breaching companies in the United Kingdom, the United States, Canada, and the Middle East, under the aliases GHOSTR and 0mid16B.United StatesBy 2024, he was also breaching companies in the United Kingdom, the United States, Canada, and the Middle East, under the aliases GHOSTR and 0mid16B.
Industries
E-commerceHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.financeHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.HealthcareHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.InsuranceHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.logisticsHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.propertyHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.recruitmentHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.RetailHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.TechnologyHis victims spanned diverse industries like healthcare, finance, logistics, technology, e-commerce, retail, insurance, property, and recruitment.