Prime Suspectz was a Brazilian hacker group active in the early 2000s and primarily known for high-volume website defacements against prominent multinational brands, media properties, and public-sector organizations. The group publicly identified itself as Brazilian and was reported to consist of four members using the aliases x-s4nd3r, k4m1k4z3, överki££, and 4n1cl4t0r. Prime Suspectz gained visibility through repeated compromises of Microsoft country websites and other internationally recognized targets, often replacing homepages with taunting or nationalist messages and then allowing normal content to be restored or redirected shortly afterward. The group repeatedly targeted Microsoft web properties, including country sites in the United Kingdom, Mexico, Saudi Arabia, and previously New Zealand, and also defaced an MSNBC sports property associated with Microsoft. Other reported victims included NASA, Nike Brazil, NEC, Nintendo, eBay, Panasonic, BMW, Chevrolet, the Australian Broadcasting Authority, and celebrity websites associated with Mel Gibson, Jennifer Aniston, and Denzel Washington. Reporting from the period consistently characterized Prime Suspectz as focusing on less well protected overseas or third-party-managed web infrastructure belonging to major organizations. Prime Suspectz's operations were centered on unauthorized access followed by visible defacement rather than destructive sabotage or confirmed theft. The group claimed to use exploits tailored to specific vulnerabilities and stated that poorly configured Microsoft IIS servers were comparatively easy to compromise. Their activity demonstrates initial access, post-exploitation control sufficient to alter web content, and basic reconnaissance in selecting exposed, high-visibility targets. Although the group claimed to target sites handling confidential or payment-related information, high-confidence reporting on its known operations chiefly supports website compromise and public messaging rather than verified data theft. The actor's messaging and victimology indicate a notoriety-driven campaign with nationalist overtones rather than espionage or financially motivated intrusion. Prime Suspectz frequently used branding, victory statements, and pro-Brazil slogans in defacements, and some incidents were framed as protests or publicity stunts. The group was also described as maintaining ties with other Brazilian and international hacker groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Prime Suspectz appears only in a generic Wikipedia navigation list of hacking groups, without any discussion tying it to the PoisonIvy content.
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.