AntiSec is a hacktivist group/movement associated with Anonymous and described in the content as including members of Anonymous and the disbanded LulzSec. It is presented as an Anonymous offshoot that particularly targeted law enforcement, military contractors, government agencies, and what it called "white hat sellouts." The content ties AntiSec to ideologically motivated intrusions, data theft, doxing, website defacement, and public leaking of stolen material. Reported AntiSec activity in the content includes the 2011-2012 breach of Stratfor, in which AntiSec hacked the Texas-based private intelligence firm, took its website offline, stole roughly 200GB of data including more than 5 million internal emails, exposed credit card and personal information from over 60,000 customers, and provided the emails to WikiLeaks for later publication as the "Global Intelligence Files." Jeremy Hammond is repeatedly identified as a key AntiSec hacker involved in the Stratfor intrusion; Hector Xavier Monsegur ("Sabu"), an Anonymous/LulzSec figure and FBI informant, is described in court records and reporting as having monitored or facilitated aspects of the operation while cooperating with the FBI. Hammond is also described as part of the Anonymous-associated groups AntiSec and LulzSec. Other operations attributed to AntiSec in the content include breaches and leaks involving the Arizona Department of Public Safety; IRC Federal; Vanguard Defense Industries; multiple law-enforcement-related organizations including the International Association of Chiefs of Police, the Boston Police Patrolmen’s Association, and the Baldwin County Sheriff’s Office; theft and release of law-enforcement data under releases such as "Shooting Sheriffs Saturday Release"; and a claimed theft of 12.36 million Apple device identifiers allegedly from an FBI laptop. The content also mentions a claimed defacement of 74 Turkish government websites. In several cases, reporting notes that some claims were made by AntiSec and were not independently confirmed. Tactics and techniques directly described in the content include SQL injection, compromise of web administration panels, abuse of weak file-upload protections, password cracking, credential reuse to access email accounts, theft of databases and email spools, website defacement, publication of stolen documents and personal data, and use of torrents/Pastebin/social platforms to distribute leaks and claims. AntiSec is also linked in the content to public exposure of police officers’ personal information, passwords, Social Security numbers, and internal communications. Known aliases and related groups directly mentioned in the content are AntiSec/Antisec, Anonymous, and LulzSec. The content does not establish AntiSec as a nation-state actor; it characterizes it as a hacktivist movement/group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AntiSec is referenced in connection with Jeremy Hammond’s role in the 2012 hack of Stratfor and the subsequent publication of stolen company emails via WikiLeaks.
Anonymous-associated hacker group involved in the Stratfor breach and publication of stolen credit card numbers and client records.
Hacktivist/anarchist hacking crew associated with Jeremy Hammond that conducted intrusions, data theft, website defacements, and leaks against law enforcement, police suppliers, private intelligence firms, and government-related targets, including the Stratfor breach.
Hacktivist group involved in the 2011 Stratfor hack, theft of millions of internal emails, and associated financial crimes using stolen Stratfor customer credit cards.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.