SnowSoul

First seen
2026-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
minimal
Resource level
individual
Actor type
criminal
Profile updated
2026-07-07 12:29:45

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:cn

Context

SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organizations. The actor sends extortion demands of around $2,000 USD, and when victims refuse to pay, leaks stolen data on hacker forums. Operations are tracked through numbered identifiers (e.g., SnowSoul ID-1265, ID-1270), suggesting a systematic, serial campaign.

Reports & references

  • dailydarkweb.net — Snowsoul Attack Hits Multiple Chinese Organizations (report)
  • dailydarkweb.net — Guangdong Caiding Market Group Faces Data Breach After Extortion (report)
  • hacknotice.com — Hualun New Materials Suffers Massive Data Breach By Snowsoul (report)

External references