TeaMp0isoN, also rendered as Team Poison or teamp0ison, was a politically oriented hacking group active in the early 2010s. The group was founded by TriCk and MLT and became known for high-profile intrusions, website defacements, data leaks, and public stunts. Junaid Hussain, later known as Abu Hussain al-Britani after joining the Islamic State, was a prominent member operating under the handle TriCk. TeaMp0isoN was publicly associated in some reporting with other anti-Western and pro-Palestinian hacktivist circles, including the Mujahideen Hacking Unit and the Pakistan Cyber Army. The group targeted government, military-adjacent, and high-visibility public-sector entities, as well as politically symbolic organizations and individuals. Reported victims and targets included NATO Croatia, NASA-associated infrastructure, British government-related entities, and prominent political figures. TeaMp0isoN also claimed activity against Facebook pages it regarded as racist or Zionist and against British far-right groups. Its operations blended ideological messaging with publicity-seeking behavior and, by some member accounts, personal challenge and notoriety. TeaMp0isoN used web application exploitation and defacement as core tradecraft. Reported activity includes SQL injection against a NASA-associated forum running vBulletin, compromise of administrator accounts, publication of leaked material, and defacement of official websites with political messages. The group also engaged in exfiltration and leaking of documents and server data, and conducted disruptive harassment operations such as automated phone-bombing of a British anti-terror hotline as a political protest. Public exposure campaigns against rivals were also part of its behavior, including threats to reveal alleged identities of LulzSec members. The actor’s capabilities therefore span initial access through exploitation of internet-facing applications, exfiltration, defacement, reconnaissance, and politically motivated post-compromise operations. TeaMp0isoN’s activity was primarily hacktivist rather than financially motivated, and available reporting does not support classifying it as a ransomware or extortion actor. Although some members later became associated with jihadist activity, TeaMp0isoN itself is best characterized as a hacktivist collective rather than a state-sponsored threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named hacking group discussed in the content as having carried out several high-profile hacks.
Hacktivist group discussed through an interview with a core member; described as conducting politically motivated attacks, including high-profile website compromises and claimed administrative access to Facebook.
Hacktivist-oriented hacking group associated here with Junaid Hussain; conducted intrusions and disruptive actions including theft of Tony Blair’s address book, phone-bombing an MI6 counter-terror hotline, and attacks on Facebook pages of British far-right groups.
Politically motivated hacktivist group engaged in hacking government websites, website defacements, and doxxing efforts aimed at exposing alleged LulzSec members.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.