SN_BlackMeta is a hacktivist DDoS-focused threat actor described as a pro-Palestinian group and as being against U.S. and Israeli interests. The group has claimed responsibility for distributed denial-of-service attacks against the Internet Archive, including activity in October 2024 that temporarily took the site offline by overwhelming its servers with traffic. Reporting also states the group conducted major DDoS attacks against financial institutions in the Middle East and was allegedly involved in attacks against Microsoft Azure. The group is described as writing in English, Russian, and Arabic. Multiple sources in the content note similarities between SN_BlackMeta and Anonymous Sudan in operations, target selection, rhetoric, and TTPs; one source says it may be linked to Anonymous Sudan, but this is presented as an assessment rather than confirmed attribution. Known alias in the provided content: sn_blackmeta.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a DDoS attack against the Internet Archive, temporarily disrupting availability during the broader October 2024 incident series.
SN_Blackmeta is a hacktivist group known for conducting major DDoS attacks against financial institutions in the Middle East and cloud service providers like Microsoft Azure.
Claimed responsibility for the multi-day DDoS attacks against the Internet Archive.
Named hacktivist-style DDoS actor (claimed pro-Palestinian motives) assessed by Radware as potentially linked to Anonymous Sudan based on operational/rhetorical similarities; a German source describes it as a Russian group (Veliky Novgorod region) claiming no state sponsorship.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.