The Kurdish hacktivist group Hezi Rash has rapidly emerged as a significant threat in the hacktivist landscape, orchestrating nearly 350 distributed denial-of-service (DDoS) attacks worldwide between August and October. According to Check Point researchers, Hezi Rash has been more active than other hacktivist groups during this period, with almost a quarter of its attacks targeting Japanese websites in retaliation for anime content depicting the burning of the Kurdish flag. Other major targets include Turkiye, Israel, Germany, and Iran, with the group leveraging DDoS-as-a-service (DaaS) platforms such as EliteStress and Abyssal DDoS v3 to amplify their operations.
Hezi Rash positions itself as a digital defender of Kurdish and Muslim communities, tying its cyberattacks to political and religious motivations. The group maintains a strong presence on social media platforms including Telegram, TikTok, YouTube, and X, and has formed alliances with established hacktivist collectives like NoName057(16), Killnet, and Keymous+. Security researchers recommend organizations bolster their defenses with Web Application Firewall (WAF) challenges, DDoS mitigation services, and enhanced monitoring of residential IP traffic to counter the growing threat posed by Hezi Rash and similar hacktivist operations.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
By early November 2025, security reporting highlighted Hezi Rash's unusually high attack volume for a group of its size and documented its use of alliances and DDoS-for-hire tooling. The reporting identified the group as an emerging hacktivist operation driving a surge in DDoS activity.
Between August and October 2025, Hezi Rash claimed responsibility for approximately 350 distributed denial-of-service attacks. Targets spanned multiple countries, including Japan, Türkiye, Israel, Germany, Iran, Iraq, Azerbaijan, Syria, and Armenia.
Hezi Rash, a Kurdish nationalist hacktivist group also known as 'Black Force in Kurdish,' was established in 2023. The group positioned itself as defending Kurdish and Muslim communities through cyber operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.