Anonymous Sudan is a disruptive threat actor best known for large-scale distributed denial-of-service operations against government agencies, critical infrastructure, hospitals, media organizations, cloud and technology providers, transportation entities, and other high-visibility targets worldwide. The group has also been tracked as AnonSudan and Storm-1359. Although it publicly presented itself as a pro-Muslim or hacktivist collective and frequently justified attacks with anti-Western, anti-Israel, or anti-LGBTQ rhetoric, multiple reporting streams linked its activity to pro-Russian geopolitical alignment, close collaboration with KillNet, and targeting patterns consistent with Russian strategic interests. Separately, U.S. authorities alleged that the operation was run by two Sudanese nationals and functioned as a cybercrime enterprise that also sold DDoS capability to other actors. The actor emerged in early 2023 and rapidly became one of the most prolific DDoS operators in the pro-Russia hacktivist ecosystem. It claimed or was linked to attacks affecting Microsoft services, OpenAI, Cloudflare’s public website, PayPal, X, UPS, Scandinavian Airlines, Netflix, the Associated Press, Archive of Our Own, the London Internet Exchange, Kenyan digital government and internet infrastructure, and numerous Israeli targets. In the Israel-Hamas conflict, Anonymous Sudan was among the most visible groups claiming attacks on Israeli government and media sites, alerting applications, and other public-facing services. It also publicly threatened and claimed attacks against organizations in countries perceived as supporting Israel, including Kenya and the United Kingdom. Its core capability is service disruption through DDoS, including application-layer and other high-volume techniques designed to overwhelm public-facing services and bypass mitigation controls. Reported impacts ranged from intermittent outages to multi-day service disruption. U.S. law-enforcement allegations state that the group operated a dedicated DDoS platform, also marketed under multiple service names, and used it both for its own operations and as a for-hire offering. In approximately one year of activity, that infrastructure was allegedly used in more than 35,000 attacks. Authorities also alleged extortion in some cases, including demands for payment to stop ongoing disruption. Anonymous Sudan’s operations were heavily propaganda-driven, with claims and threats disseminated through Telegram in near real time. The group frequently paired disruptive attacks with ideological messaging, opportunistic geopolitical narratives, and attempts to amplify fear or reputational damage. Despite occasional claims of more consequential attacks, the most consistently corroborated activity was denial-of-service against public-facing services rather than deep network compromise. Some claimed attacks on industrial or critical infrastructure targets were not independently confirmed or appeared to have limited real-world effect. The actor’s attribution remains contested at the narrative level but clearer at the operational level in some legal proceedings: security researchers widely assessed the group as pro-Russian or closely tied to the KillNet ecosystem, while U.S. prosecutors alleged direct control by two Sudanese brothers. Taken together, Anonymous Sudan is best characterized as a high-tempo disruptive actor combining hacktivist branding, geopolitical messaging, and cybercrime-style DDoS-for-hire operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted or claimed high-profile attacks against Israeli government and media targets and was cited as collaborating with SiegedSec on claimed DoS attacks against Israeli ICS and infrastructure.
Hacktivist group claiming DDoS-style disruptions against Israeli and Kenyan targets in response to geopolitical positions related to Israel.
Hacktivist-branded activity; described as distinct from the original 'OpSudan' and collaborating with Killnet against Western targets, illustrating blurred lines between hacktivism and state-aligned activity.
Mentioned as part of a list of proliferating hacktivist names; no specific operations described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.