Internet Feds was a short-lived hacktivist hacking collective active primarily between late 2010 and mid-2011 and closely associated with prominent members of Anonymous, including Hector Xavier Monsegur (Sabu). Reported participants included Sabu, Ryan Ackroyd, Jake Davis, Darren Martyn, and Donncha O’Cearrbhail. The group is linked to a campaign of disruptive and destructive intrusions targeting corporations, media organizations, political entities, and internet security firms. Internet Feds operations included unauthorized access to victim systems, theft of confidential information, public disclosure of stolen data, website defacement, and hijacking of victims’ email and social-media accounts. High-profile activity attributed to the collective included the compromise of HBGary and HBGary Federal, the theft of large volumes of internal communications and user-related data, the intrusion into Fox Broadcasting systems involving applicant data for a television program, and a conspiracy to hack the website of Fine Gael in Ireland. The group’s tradecraft, as directly supported here, centered on initial access, data theft, public leaking, account compromise, and disruptive post-compromise actions rather than financially motivated extortion. Internet Feds overlapped operationally and personnel-wise with the broader Anonymous ecosystem and preceded the formation of LulzSec in May 2011. Its activity fits the pattern of politically tinged hacktivist operations that combined intimidation, embarrassment, and disruption of targets through unauthorized access and disclosure. No high-confidence evidence here supports ransomware activity or a dominant financial motive.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A hacking collective that conducted intrusions, theft and disclosure of confidential information, account hijacking, and website defacements against political, security, and media targets.
Small crew around Sabu that preceded Lulzsec and conducted the HBGary intrusion, including compromise of the website, Twitter account, and email database, followed by publication of stolen emails.
Hacktivist group mentioned as part of the conspiracy involving "Sabu"; no additional operational detail provided beyond participation in hacking activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.