SnowSoul
- First seen
- 2026-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- minimal
- Resource level
- individual
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:29:45
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:cn
Context
SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organizations. The actor sends extortion demands of around $2,000 USD, and when victims refuse to pay, leaks stolen data on hacker forums. Operations are tracked through numbered identifiers (e.g., SnowSoul ID-1265, ID-1270), suggesting a systematic, serial campaign.
Reports & references
- dailydarkweb.net — Snowsoul Attack Hits Multiple Chinese Organizations (report)
- dailydarkweb.net — Guangdong Caiding Market Group Faces Data Breach After Extortion (report)
- hacknotice.com — Hualun New Materials Suffers Massive Data Breach By Snowsoul (report)