0cx00iq is a self-identified threat actor associated with an alleged cyber intrusion targeting Kuwait’s Public Authority for Civil Information, a government body responsible for civil identity, population statistics, and mapping-related data. The actor publicly framed the operation as retaliation for alleged aggression against Iraqi fishermen and positioned the activity as part of a broader nationalist response tied to Iraqi sovereignty. Based on the available reporting, 0cx00iq appears to present as a politically motivated or hacktivist-style actor rather than a formally attributed state-sponsored group. The actor claimed to have compromised multiple core government information systems and to have obtained large volumes of sensitive civil, demographic, identity, and mapping data relating to Kuwaiti citizens. The same operation was also described as involving destructive activity, including deletion of government mapping data, indicating both exfiltration and destructive intent. In addition, the actor allegedly attempted to monetize the stolen information by offering it for sale, showing a blend of ideological messaging and opportunistic criminal behavior. Observed and claimed behaviors associated with 0cx00iq include initial access against government systems, data theft and exfiltration, destructive post-compromise actions, and public coercive messaging threatening additional attacks against states perceived as acting against Iraqi interests. High-confidence targeting in the available reporting centers on Kuwait’s government and civil identity infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.