Threat Actor Profiling: Moneyistime (a.k.a. @69.pdf)
2026.07.28
✅ Report Title: Threat Actor Profiling: Moneyistime (a.k.a. @69.pdf)
✅ Executive Summary:
📌 Who Is Moneyistime?
- On June 28, 2024, they joined the dark web hacking forum RAMP under the nickname Moneyistime and started their forum activities.
- Activity has also been confirmed on other DDW forums such as Leakbase, Duty-Free, DarkForums, and Exploit, in addition to RAMP.
- RAMP and Leakbase were used for data leak threats and actual leaks, while Duty-Free was used as a means of recruiting team members and purchasing Initial Access. After RAMP and Leakbase were shut down, DarkForums and Exploit were confirmed to be used as the main channels for data sales and leaks.
- Moneyistime has been active on the Exploit forum since 2022 under the username 69.pdf, initially focusing on Access transactions, and it has been confirmed that from April 2026 they switched to data sale and leak activities.
📌 Moneyistime's Activity Patterns
- Mainly conducts attacks targeting Chinese-speaking countries and South Korea, and uploads attack verification posts on forums using Chinese, Russian, and English.
- Among South Korean companies and institutions, targets have included automotive parts manufacturer Company Y (2025-09-11), university hospital Company A (2026-01-27), defense company Company B (2026-02-12), automotive parts manufacturer Company C (2026-02-22), pharmaceutical company Company D (2026-03-02), precision manufacturing company Company E (2026-05-28), and electric vehicle parts manufacturer Company F (2026-07-04).
- Analysis of activity times, including post and comment timestamps, found that activity mainly occurred between 14:00 and 2:00 the next day (UTC+9), with the highest frequency at 20:00.
- Given the main attack targets and activity times, it is highly likely that the actor is operating in the Asian region.
📌 Moneyistime's Attack Patterns
- Alongside file encryption, demands for money and threats of data leak occur within a set time frame, showing characteristics similar to a ransomware attack from a behavior-based perspective.
- Given that the same victim company was posted on the BEAST ransomware's DLS (Data Leak Site), the Moneyistime user is presumed to be associated with the BEAST ransomware operation group or its variant affiliates.
✅ Threat Detection Recommendations and Mitigation Measures
-
The attacker is presumed to be targeting servers or PCs with weak RDP security, as they capture drive information after successfully connecting via Remote Desktop (RDP) and use it as evidence screenshots of a successful attack.
- Minimize externally exposed RDP services and apply VPN- and MFA-based access control to block unauthorized remote access.
- The Moneyistime user continuously attacks South Korean companies and leaks data on the DDW, so continuous monitoring of this user is necessary.
🧑💻 Author: S2W TALON
👉 Contact us: https://s2w.inc/en/contact
*The full report is available upon request or with a subscription to the S2W platform.