AnonSecKh is a Cambodian hacktivist group also tracked as ANON-KH and Bl4ckCyb3r. The group became prominent for a sustained campaign against Thai organizations in 2025 following a border incident involving the death of a Cambodian soldier, and publicly claimed responsibility for dozens of attacks during that period. Reporting attributes a wave of disruptive activity against Thai entities to the group, primarily consisting of distributed denial-of-service operations and website-focused attacks framed as retaliation in the context of Cambodia-Thailand tensions. AnonSecKh is best characterized as a politically motivated hacktivist actor focused on disruptive operations rather than covert espionage or financially motivated intrusion. High-confidence reporting ties the group to attacks on Thai organizations, including numerous Thai websites, with activity aligned to geopolitical events and nationalist messaging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AnonSecKh is a Cambodian hacktivist group that attacked multiple Thai websites, contributing to escalating cyber tensions between Cambodia and Thailand.
Cambodian hacktivist group conducting politically motivated cyber attacks against Thai government, military, manufacturing, and finance sectors.
Conducting politically motivated DDoS attacks against Thai organizations, framed as retaliation tied to a Thailand–Cambodia border incident.
Hacktivist actor conducting politically motivated DDoS and website defacement campaigns against Thai government/military and other organizations amid border tensions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.