The Syrian Electronic Army (SEA) is a pro-Assad threat actor aligned with the Syrian government’s interests and widely associated with cyber operations conducted in support of the Assad regime during the Syrian civil war. The group became internationally known for website defacements, social media account compromises, DNS hijacking, propaganda distribution, and data breaches targeting Western media organizations, corporate entities, NGOs, and government-related targets. SEA operations have been used to place pro-Assad messaging on compromised websites and social media feeds, spread false information, and retaliate against organizations perceived as hostile to Syria. SEA is particularly known for social engineering-enabled account compromise and infrastructure manipulation. Publicly attributed operations include compromises of prominent media and social media properties, including the Associated Press Twitter account, where a false White House bombing report caused major short-term market disruption, as well as DNS hijacking incidents affecting major news and internet platforms. The group has also been linked to defacements of U.S. Army websites in 2015 and to the 2014 Forbes intrusion, which involved both credential leakage and fraudulent content publication. Beyond overt propaganda operations, SEA-linked activity has been associated with lower-profile malware operations against Syrian opposition targets. Reporting has also described an ecosystem of trolls, honeypot personas, and hackers linked to SEA that worked in concert to build trust with targets, distribute malicious links, and support influence and intrusion objectives. Known tradecraft associated with the group includes spoofing, initial access via social engineering, website defacement, credential theft, data breaches, and infrastructure hijacking for message amplification. The actor is commonly referred to simply as the Syrian Electronic Army or SEA. Its dominant motivation is influence operations in service of pro-Assad political objectives, with espionage-style and disruptive effects appearing secondary to propaganda, retaliation, and narrative control.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a historical comparison to a prior defacement of Army websites.
Referenced as a historical example of a prior defacement of U.S. Army-related websites.
Mentioned as an example of a known actor that has used Arabic-language lure documents disguised as government forms in targeted campaigns.
Attributed with the 2014 attack on Forbes that leaked over 1 million user accounts and resulted in fake news stories being posted to forbes.com.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.