Keymous+ is a North African hacktivist actor assessed to have originated in Algeria that combines political messaging with sustained distributed denial-of-service operations and apparent ties to a commercial DDoS-for-hire ecosystem. The group emerged publicly in late 2023, initially framing activity as pro-Palestinian and anti-Israel under “Hack for Humanity” style branding, but later expanded into a broader geopolitical disruption actor active across Middle Eastern, European, and South Asian crises. Researchers have described it as a hybrid actor whose public persona blends ideological hacktivism, propaganda amplification, coalition activity, and promotion of stressor-style DDoS services. Keymous+ is best known for high-volume DDoS campaigns against government and public-sector targets, and has repeatedly been identified as one of the most active hacktivist groups during regional escalations involving Israel, Iran, Gulf states, and India. It has also participated in coordinated campaigns with other hacktivist groups including DieNet, NoName057(16), Mr Hamza, AnonSec, Inteid, and Moroccan Dragons. Public reporting describes an internal division between an Alpha Team associated with breach-and-leak activity and a Beta Team responsible for DDoS operations, with the Beta Team accounting for most confirmed activity in recent periods. Confirmed and claimed targeting spans government, telecommunications, financial services, transportation, health care, education, and energy. High-confidence reporting identifies Morocco, Saudi Arabia, Sudan, India, and France among its most targeted countries, while additional campaigns have targeted Israel, Jordan, Kuwait, Oman, and other Gulf states. During Middle East conflict periods, Keymous+ was repeatedly cited as a leading source of attack claims and disruptive activity, especially against government institutions. The group has also been linked to campaigns against European financial institutions and to anti-India hacktivist operations during India-Pakistan tensions. Its core tradecraft centers on DDoS using publicly available or commercialized attack infrastructure, including amplification and direct-flooding techniques across multiple network and application-layer protocols. Reporting also indicates public uptime verification, structured target announcements, coalition coordination through Telegram, and propaganda-driven amplification of attack claims. Some reporting attributes data-theft and breach claims to the group, including claimed exfiltration from Israeli and Gulf government entities, but the actor is primarily characterized by disruptive operations rather than sophisticated intrusion tradecraft. Public claims are assessed to be materially inflated relative to independently verified attack telemetry. The group’s dominant motivation is hacktivism, although its overlap with commercial DDoS services indicates a blurred boundary between ideological operations and service monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Contributes DDoS activity and propaganda amplification; specifically noted for some of the highest-volume DDoS campaigns of the conflict.
High-volume hacktivist actor active in Middle East crisis mobilization, contributing attack claims, rhetoric, target lists, and coalition signaling.
North African hybrid hacktivist and commercial DDoS actor assessed as highly prolific in global DDoS claim activity, using a commercial DDoS-as-a-Service platform, alliance operations, and politically themed campaigns targeting government and other public-facing infrastructure.
Conducting DDoS campaigns against European financial institutions, with activity peaking around elections and heightened political tension.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.