Anonymous Sudan is a DDoS-focused threat group active since at least January 2023. It is also referred to as AnonSudan and Storm-1359. Multiple sources in the provided content describe it as a self-proclaimed hacktivist operation, while U.S. authorities describe it as a cybercriminal group and DDoS-for-hire business. A federal grand jury indictment unsealed in the United States charged two Sudanese nationals, Ahmed Salah Yousif Omer and Alaa Salah Yusuuf Omer, with allegedly operating and controlling the group. U.S. authorities allege the group conducted more than 35,000 DDoS attacks in roughly a year, caused more than $10 million in damages to U.S. victims, and used a platform called the Distributed Cloud Attack Tool (DCAT), also known as Godzilla, Skynet, and InfraShutdown; authorities seized and disabled this infrastructure in March 2024. The group’s activity in the provided content is centered on large-scale distributed denial-of-service attacks, including attacks that often lasted for days and rendered victim websites and networks inaccessible. Reported targeting spans critical infrastructure, government agencies, hospitals, media organizations, cloud and technology providers, telecommunications, airlines, banks, and online platforms. Named victims and claimed targets in the content include Microsoft services, Cloudflare’s website, OpenAI/ChatGPT, X/Twitter, PayPal, UPS, Scandinavian Airlines, Netflix, the Associated Press, Archive of Our Own, the London Internet Exchange, Cedars-Sinai Medical Center, U.S. government entities including the Department of Justice, Department of Defense, FBI, and State Department, Kenyan internet infrastructure, and Israeli targets including alert applications and media sites such as The Jerusalem Post. The group publicly frames some operations as motivated by pro-Islamic, anti-Western, anti-LGBTQ+, or pro-Palestinian causes, and it has used Telegram extensively to claim attacks, threaten future operations, and issue warnings. The content also states that the group has attempted extortion, including a $30,000 bitcoin demand during the AO3 attack, and that U.S. prosecutors allege it sold DDoS attacks as a service and extorted some victims. Regarding attribution, the provided content contains repeated assessments from researchers, media reporting, and Mandiant that Anonymous Sudan is linked to, affiliated with, aligned with, or collaborating with pro-Russian actors, especially KillNet. Mandiant identifies Anonymous Sudan as a pro-Russia hacktivist group posing a viable threat to the 2024 Paris Olympics and assesses that it became KillNet’s most prolific affiliate in 2023, accounting for 63% of identified DDoS attacks claimed by the KillNet collective in one reviewed period. The content also states that Anonymous Sudan collaborated with Killnet and that its operations and messaging often aligned with Russian strategic interests. At the same time, some reports characterize Russian links as suspected or assessed rather than definitively proven. The content also notes no known connection to the original Anonymous collective despite the name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist-branded activity; described as distinct from the original 'OpSudan' and collaborating with Killnet against Western targets, illustrating blurred lines between hacktivism and state-aligned activity.
Mentioned as part of a list of proliferating hacktivist names; no specific operations described in this content.
Anonymous Sudan is a hacktivist group conducting DDoS attacks against Western and Israeli targets, with suspected links to Russian interests. Their operations are as much information operations as technical attacks.
DDoS-for-hire operation that marketed attacks as hacktivism while selling disruptive services to paying customers, conducting extortion, and targeting hospitals, cloud providers, government services, financial institutions, universities, and major technology platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.