{
	"id": "b10811b4-ea49-458d-9a5c-7309cc0ff4a4",
	"created_at": "2026-04-06T00:08:35.173884Z",
	"updated_at": "2026-04-10T03:28:09.053409Z",
	"deleted_at": null,
	"sha1_hash": "e03ef07e2bcc2db0d09fb05063bef97847f06f75",
	"title": "NetSec, USDoD - Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 58946,
	"plain_text": "NetSec, USDoD - Threat Group Cards: A Threat Actor\nEncyclopedia\nArchived: 2026-04-05 19:41:55 UTC\nHome \u003e List all groups \u003e NetSec, USDoD\n Other threat group: NetSec, USDoD\nNames\nNetSec (self given)\nScarFace_TheOne (self given)\nUSDoD (self given)\nCountry Spain\nMotivation Financial gain\nFirst seen 2020\nDescription\n(Cyble) During our Deepweb search in various forums, security researchers at the\nLab identified a prolific TA going by the name NetSec aka ScarFace_TheOne aka\nScarfac33 and targeting the U.S. infrastructure. Our research indicated that the TA\nhas been active on the forum for over two years, taking part in various cyberattacks\nwith diverse geographical and dynamic industry footprints. The TA’s malicious\ncyber activities have helped earn an aggressive reputation, besides resulting in the\nTA being widely endorsed and acclaimed by other notable malicious actors such as\nPompompurin, Holistic-K1ller, and IPegFemBoys.\nObserved\nSectors: Defense.\nCountries: USA.\nTools used\nOperations performed\nDec 2022\nFBI’s Vetted Info Sharing Network ‘InfraGard’ Hacked\nSep 2023\nAirbus investigates data leak allegedly involving thousands of\nsuppliers\nhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=d82e1bf8-26e5-4c2e-bce0-eff36f55c532\nPage 1 of 2\n\nApr 2024\nHackers leak 2.7 billion data records with Social Security numbers\nJul 2024\nHacktivist Entity USDoD Claims to Have Leaked CrowdStrike’s\nThreat Actor List\nCounter operations Oct 2024\nOperation “Data Breach”\nUSDoD hacker behind National Public Data breach arrested in Brazil\nInformation\nLast change to this card: 30 June 2025\nDownload this actor card in PDF or JSON format\nSource: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=d82e1bf8-26e5-4c2e-bce0-eff36f55c532\nhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=d82e1bf8-26e5-4c2e-bce0-eff36f55c532\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/showcard.cgi?u=d82e1bf8-26e5-4c2e-bce0-eff36f55c532"
	],
	"report_names": [
		"showcard.cgi?u=d82e1bf8-26e5-4c2e-bce0-eff36f55c532"
	],
	"threat_actors": [
		{
			"id": "80edca9f-dcd6-491e-92f3-87ad1f575631",
			"created_at": "2023-10-14T02:03:14.694988Z",
			"updated_at": "2026-04-10T02:00:05.021046Z",
			"deleted_at": null,
			"main_name": "NetSec",
			"aliases": [
				"NetSec",
				"Operation Data Breach",
				"ScarFace_TheOne",
				"USDoD"
			],
			"source_name": "ETDA:NetSec",
			"tools": [],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "82a51997-1402-41c3-86df-6f9e522b2ba8",
			"created_at": "2024-04-27T02:00:03.554045Z",
			"updated_at": "2026-04-10T02:00:03.63698Z",
			"deleted_at": null,
			"main_name": "USDoD",
			"aliases": [],
			"source_name": "MISPGALAXY:USDoD",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		}
	],
	"ts_created_at": 1775434115,
	"ts_updated_at": 1775791689,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/e03ef07e2bcc2db0d09fb05063bef97847f06f75.pdf",
		"text": "https://archive.orkl.eu/e03ef07e2bcc2db0d09fb05063bef97847f06f75.txt",
		"img": "https://archive.orkl.eu/e03ef07e2bcc2db0d09fb05063bef97847f06f75.jpg"
	}
}