Electronic Disturbance Theater (EDT) is a hacktivist collective of artists and activists associated with early forms of electronic civil disobedience. The group is known for developing FloodNet, a tool intended to let supporters participate in coordinated denial-of-service style online protests or “virtual sit-ins.” EDT publicly framed disruptive computer-based actions as political expression and supported politically motivated hacking in anti-nuclear and protest contexts. Known members associated with the group include Ricardo Dominguez, Carmin Karasic, Paco Nathan, Brett Stalbaum, and Stefan Wray. EDT is notable as an early example of politically motivated cyber activity that blended technical disruption with messaging and public advocacy. Its activity and public positioning align with hacktivism rather than financial crime or espionage. The group’s methods and advocacy are tied to denial-of-service activity and online protest tactics designed to amplify political causes, particularly through public-facing disruption and symbolic action. EDT has been cited in discussions of the historical development of hacktivism and electronic civil disobedience.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist/art-activist collective publicly supporting politically motivated hacking and associated with development of FloodNet software.
Hacktivist collective associated with formalizing ‘Electronic Civil Disobedience’ concepts and developing FloodNet, a Java applet used to coordinate virtual sit-ins/denial-of-service activity in support of activist causes (notably Zapatista-related actions).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.