LulzRaft is a little-documented hacking persona or small collective associated with a 2011 compromise of the Conservative Party of Canada website. The group claimed responsibility for posting a fabricated news item alleging that Prime Minister Stephen Harper had suffered a medical emergency, indicating an operation centered on website compromise and public deception rather than data theft or destructive impact. Available reporting characterizes the incident as unauthorized access to the party website and a prank-like hoax intended to generate confusion and publicity. High-confidence information supports only a narrow activity profile: initial access to a public-facing web property, post-compromise manipulation of site content, and spoofing through the publication of false information. There is no corroborated evidence in the available material that LulzRaft conducted broader sustained campaigns, ransomware operations, espionage, or financially motivated intrusion activity. The actor is primarily notable for the Harper hoax targeting a Canadian political organization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely imitator group that claimed responsibility for unauthorized access to the Conservative party website and posting a false news item as a political hoax.
LulzRaft
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.