New World Hackers is a hacktivist group that publicly claimed responsibility for the October 2016 DDoS attack against DNS provider Dyn, alongside Anonymous and later SpainSquad, but the available reporting cited scant evidence and did not confirm those claims. A representative using the alias Prophet said the group was working with Anonymous and described the target as "anything big," claiming the Dyn attack was retaliation for Ecuador cutting Julian Assange’s internet access. Multiple sources in the content state that Flashpoint and FireEye assessed the group’s public claims as dubious or likely false; Flashpoint reportedly called them imposters, and FireEye noted a history of falsely claiming high-profile attacks and questioned whether the group had the capability to conduct an attack at Dyn’s scale. The Dyn incident itself was assessed as involving Mirai-powered IoT botnet activity. The content also reports that New World Hackers had previously claimed responsibility for similar attacks targeting sites such as the BBC and ESPN.com. Known alias in the provided content: new_world_hackers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the large-scale Dyn DNS DDoS attack and said it was coordinated with Anonymous in protest of Julian Assange's loss of internet access. The article notes researchers were skeptical and cited the group's history of false claims.
Claimed or implied responsibility for the Dyn DNS DDoS attack, though Flashpoint assesses such claims as dubious/likely false and instead attributes the activity to amateur forum-based actors.
Self-claimed responsibility (unconfirmed) for the 21 Oct 2016 Dyn DDoS; described as leveraging the Mirai-infected IoT botnet to generate massive DNS request floods; previously claimed similar attacks against BBC and ESPN.com per the content.
Hacktivist group referenced as participating in the Dyn DDoS incident (Mirai botnet mentioned).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.