Threadlinqs IntelligenceStart free

Threat actorN/ATracked since 2026-04

BonJoviGoesHard

Also known as:Dr. TubeBissa Operator

As of 2026-05-30, BonJoviGoesHard is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, threat intel. Also known as Dr. Tube, Bissa Operator. ATT&CK coverage spans 37 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1059.004 (Unix Shell), T1071.001 (Web Protocols).

Tracked threats
21 critical · 1 high
First seen
2026-04-22
Last seen
2026-04-27
ATT&CK techniques
37across 2 of 2 threats
Related CVEs
2Referenced by its activity
Attribution
N/ANation or origin
Nation: N/A · 2 tracked threat(s) · Categories: VULNERABILITY, THREAT_INTEL

Activity timeline

BonJoviGoesHard appears in 2 tracked threats between and .

ATT&CK techniques observed

37 techniques observed across 2 of 2 tracked threats · Resource Development (6), Credential Access (5), Exfiltration (5), Discovery (4), Collection (3), Execution (3)
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1059.004 Unix Shell — Executionobserved in 2 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 2 tracked threats
  • T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 2 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1102.002 Bidirectional Communication — Command and Controlobserved in 2 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1552.001 Unsecured Credentials — Credential Accessobserved in 2 of 2 tracked threats
  • T1552.005 Cloud Instance Metadata API — Credential Accessobserved in 2 of 2 tracked threats
  • T1560.001 Archive via Utility — Collectionobserved in 2 of 2 tracked threats
  • T1567.002 Exfiltration to Cloud Storage — Exfiltrationobserved in 2 of 2 tracked threats
  • T1580 Cloud Infrastructure Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 2 tracked threats
  • T1592 Gather Victim Host Information — Reconnaissanceobserved in 2 of 2 tracked threats
  • T1595 Active Scanning — Reconnaissanceobserved in 2 of 2 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked BonJoviGoesHard activity