RipperSec
RipperSec is a hacktivist collective with Malaysian roots, also referred to as Cyb3rDrag0nzz/Cyb3r Drag0nz. The group is described as ideologically motivated, publicly aligning with Muslim identity and pro-Palestinian causes, and framing operations against countries or entities it perceives as pro-Israel or hostile to Palestinian interests. Content also places RipperSec among globally distributed pro-Iran-aligned hacktivist ecosystems and states it formally integrated into the Cyber Islamic Resistance / CIR Electronic Operations Room, an umbrella coordinating multiple aligned teams. RipperSec’s observed activity is centered on disruptive and propaganda-oriented operations rather than financially motivated cybercrime. Reported tactics include DDoS attacks, website defacements, and public messaging. The group has been described as one of the most active actors in some datasets, repeatedly targeting Israeli government bodies such as the Israel Innovation Authority and Export Institute, and conducting DDoS campaigns against Israeli government and drone-related assets with time-specific disruption announcements. Additional reporting states it targeted India, continued targeting Israel while adding South Korean government and private-sector entities, and justified South Korean targeting by accusing the country of supplying weapons and armored vehicles to Israel. In UK reporting, RipperSec was described as a pro-Palestinian group that opportunistically targeted the UK in August 2024. Telegram is described as RipperSec’s primary platform for communication, rebranding, continuity, and audience management. Reporting notes repeated channel migrations and rebranding, use of backup channels, impersonation warnings, and promotion of Keet as a backup communications option. Earlier Telegram biographies described RipperSec as a Malaysia hacktivist collective; by January 2025 one biography described it as a non-governmental and non-profit organization focused on education, research, and pentesting. The group repeatedly promoted MegaMedusa, described in the content as a NodeJS-based DDoS tool provided by the RipperSec team, and shared related GitHub and donation links. Reporting also notes donation-based support through Sociabuzz and cryptocurrency wallets, with no evidence in the provided content of ransom demands, paid victim extortion, or structured victim-focused monetization. Some content also describes RipperSec as a pro-Russia group increasing activity against EU member states, targeting public administration, media/entertainment, and transport sectors, with a claimed intent to target OT. The provided content does not reconcile this with the separate reporting that consistently describes RipperSec as pro-Palestinian/pro-Iran-aligned, so both characterizations appear in source reporting.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malaysian group referenced as operating separate infrastructure distinct from Keymous+ and EliteStress.
Southeast Asian hacktivist group integrated into CIR operations, conducting DDoS and website defacement against Israeli targets.
Hacktivist group integrated into the Electronic Operations Room during the 2026 escalation.
Named participant joining the Cyber Islamic Resistance umbrella coalition; no specific operations detailed beyond coalition membership.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.