Skip to content

Threat actor

SearchInform

Last fetched

SearchInform is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

As a SORM provider, SearchInform enables the Russian authorities to monitor, intercept, and analyze communications data including phone conversations, emails, and text messages transmitted across Russian networks. The company possesses special authorization to sell and implement SORM surveillance technology under license from the Federal Security Service (FSB) of Russia. In 2019, the company announced the development of ProfileCenter, a psychological surveillance software that monitors and analyzes all employee communications in real-time. The system builds psychological profiles of employees based on their communications, assessing motivation levels, ideological beliefs, and loyalty metrics. The technology can detect criticism of a company, and monitors emails, social media platforms, and messaging services. Founded in 1995 as SoftInform, it rebranded to SearchInform in 2009 and is headquartered in Moscow.

Techniques by tactic

No ATT&CK techniques are recorded for SearchInform in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to SearchInform today — this states the absence of a published link, not that SearchInform has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from SearchInform into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.