LulzSec Black is a pro-Palestinian hacktivist group distinct from the original 2011 LulzSec collective. It operates as a hybrid actor that combines ideological messaging around Palestinian solidarity and anti-Israel themes with cyber intrusion claims, website defacements, disruptive attacks, alleged data theft, and the sale of purportedly stolen data. The group has also used mainstream and encrypted social platforms to amplify propaganda, recruit followers, distribute tools, and direct audiences toward its operational channels. Observed activity links LulzSec Black to defacement operations, claimed breaches affecting Indian entities, and campaigns framed against Israeli targets. Reporting also associates the group with DDoS and system-disruption activity against air and sea navigation systems and alerting systems. Its public-facing behavior emphasizes branding, multilingual messaging, and symbolic operations intended to maximize visibility as much as technical effect. The group has been described as using defacements as signaling and amplification mechanisms rather than purely technical end goals. LulzSec Black has maintained a broader digital ecosystem that included forum personas, Telegram channels and bots, chat spaces, and tool-distribution channels. This infrastructure has been used to advertise alleged breaches, facilitate contact for data sales, circulate operational updates, and promote a dedicated DDoS tool. The actor’s repeated redirection of audiences from public posts and social media into private messaging infrastructure reflects an organized approach to propaganda, coordination, and monetization. Known aliases include LulzSec Black 🇵🇸 and lulzsec_black. The group is best characterized as a politically motivated hacktivist actor with cybercrime-style monetization elements, using defacement, disruption, alleged exfiltration, and propaganda to support pro-Palestinian and anti-Israel narratives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Iran hacktivist group framing operations around Palestinian solidarity and targeting entities perceived as aligned with Israel.
Hacktivist group blending ideological pro-Palestinian messaging with cyber intrusions, website defacements, data leak claims, structured data sales, Telegram-based coordination, and DDoS tool distribution.
LulzSec Black is a hacktivist group involved in cyberattacks against Israeli targets, likely using DDoS and data leak tactics.
Focuses on DDoS and disruption of critical infrastructure systems in Israel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.