Home/Threat Actor/Anonymous Sudan
Threat Actor

Anonymous Sudan

anonymous_sudan · russia_aligned_false_flag_hacktivism · active since 2023

Anonymous Sudan (Skynet Stress Tester / Godzilla Botnet / Storm-1359 / InfraShutdown) is a hacktivism cluster of disputed origin, operationally publicly self-identifying as Sudanese hacktivism but Western analytical consensus widely treats Anonymous Sudan as a Russia-aligned operation using Sudanese identity as operational cover or false-flag rather than genuinely Sudanese hacktivism (supported by multiple operational-pattern data points: cluster operational language patterns aligning with Russia-speaking organized cyber operations rather than Sudanese- Arabic-speaking patterns, operational targeting consistently aligning with Russian state foreign-policy interests rather than Sudanese political interests, cluster public messaging explicitly endorsing Killnet and broader Russia-aligned hacktivism narratives, and cluster operational sophistication substantially exceeding what would be operationally plausible for Sudanese hacktivism originating in a country with limited cybercrime infrastructure during active civil war April 2023+)

active from approximately January 2023 through March 2024 when FBI law-enforcement action effectively terminated cluster operations under that brand identity.

most operationally consequential operation the June 2023 Microsoft 365 + Outlook + OneDrive sustained DDoS attacks producing operational service disruption for Microsoft 365 customers globally for multiple hours across multiple incident windows (Microsoft Storm-1359 attribution, demonstrating cluster operational capability to impact one of the most operationally resilient cloud-service providers globally)

other high-profile operations including Scandinavian Airlines SAS (February 2023), X (Twitter) (August 2023), Cloudflare and Tumblr (October 2023, operationally significant because Cloudflare is itself a major DDoS protection vendor), and Israeli targeting during October 2023 Hamas-Israel war period with public messaging framing operations as anti-Israeli solidarity-with-Palestinians hacktivism (operational tradecraft remaining consistent with earlier Russia-aligned-targeting patterns)

March 15 2024 FBI law-enforcement action (unsealed October 2024) arresting and indicting two Sudanese national brothers Ahmed Salah Yousif Omer (born ~1999) and Alaa Salah Yusuf Omer (born ~1996) as cluster operators with conspiracy to damage protected computers charges carrying maximum life imprisonment sentences, plus disruption of Skynet Stress Tester DDoS-for-hire commercial service operating alongside hacktivism activity, arrests complicating analytical framing of cluster origin (at least some cluster operators genuinely Sudanese individuals though operational targeting and characteristics align with Russia- aligned hacktivism, suggesting Russia-aligned operational coordination or financial sponsorship of Sudanese operators rather than direct Russian-operator cluster identity).

russia_aligned_false_flag_hacktivism confidence: high 16 aliases
Sigma rules93 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Anonymous Sudan (also tracked as Skynet Stress Tester, Godzilla Botnet, Storm-1359 [Microsoft], InfraShutdown) is a hacktivism cluster of disputed origin, operationally publicly self- identifying as Sudanese hacktivism but Western analytical consensus widely treats Anonymous Sudan as a Russia-aligned operation using Sudanese identity as operational cover or false- flag rather than genuinely Sudanese hacktivism. The cluster was active from approximately January 2023 through March 2024 when FBI law-enforcement action effectively terminated cluster operations under that brand identity. The Sudanese-identity-as-false-flag analytical framing is supported by multiple operational-pattern data points: First, the cluster's primary operational language and Telegram- channel coordination patterns align with Russia-speaking organized cyber operations rather than Sudanese-Arabic-speaking patterns.

Second, operational targeting consistently aligns with Russian state foreign-policy interests (NATO-country government targeting, Western corporate technology targeting, opposition to Western sanctions on Russia) rather than Sudanese political interests. Third, cluster public messaging has explicitly endorsed Killnet (already covered as killnet.yaml) and broader Russia-aligned hacktivism narratives. Fourth, cluster operational sophistication and tooling capability substantially exceeds what would be operationally plausible for Sudanese hacktivism originating in a country with limited cybercrime infrastructure during a period of active civil war (April 2023+).

The Microsoft 365 attacks alone (June 2023) required operational capability that Sudanese hacktivism originating in Sudan during active civil-war period would not plausibly possess. Modern Western vendor consensus (Microsoft Storm-1359 naming, CrowdStrike, Mandiant, Recorded Future, others) treats Anonymous Sudan as Russia-aligned despite the Sudanese-identity-marketing. The March 2024 FBI law-enforcement action complicates the analytical framing.

On March 15, 2024 (unsealed October 2024), US Department of Justice US Attorney's Office Central District of California arrested and indicted two Sudanese national brothers as Anonymous Sudan operators
  • Ahmed Salah Yousif Omer (born approximately 1999, alleged cluster operator and Skynet Stress Tester operator)
  • Alaa Salah Yusuf Omer (born approximately 1996, alleged cluster operator) The indictments charged the brothers with conspiracy to damage protected computers and additional related charges carrying maximum sentences of life imprisonment. The FBI also disrupted Anonymous Sudan operational infrastructure including the Skynet Stress Tester DDoS-for-hire commercial service that operated alongside the cluster's hacktivism activity. The arrests effectively terminated Anonymous Sudan operations under that brand identity. The arrests complicate the analytical framing of cluster origin , at least some cluster operators were genuinely Sudanese individuals, though operational targeting and characteristics align with Russia-aligned hacktivism, suggesting Russia-aligned operational coordination or financial sponsorship of Sudanese operators rather than direct Russian-operator cluster identity. The analytical framing remains operationally complex. The cluster's most operationally consequential operation was the June 2023 Microsoft 365 + Outlook + OneDrive sustained DDoS attacks producing operational service disruption for Microsoft 365 customers globally for multiple hours across multiple incident windows. Microsoft publicly confirmed the attacks in a June 16, 2023 disclosure and tracked the cluster under the Storm-1359 identifier. The Microsoft 365 attacks were operationally consequential beyond the immediate service disruption because they demonstrated Anonymous Sudan operational capability to impact one of the most operationally resilient cloud-service providers globally, Microsoft 365 is engineered for substantial DDoS resilience, and operational disruption of that scale required substantial cluster operational capability.
Other high-profile operations include
  • Scandinavian Airlines SAS (February 2023, Nordic-country impact)
  • X (Twitter) (August 2023, brief service disruption)
  • Cloudflare and Tumblr (October 2023, operationally significant because Cloudflare is itself a major DDoS protection vendor)
  • Israeli targeting during October 2023 Hamas-Israel war period (operations against Israeli government, financial- services, healthcare, media, and critical-infrastructure targets, with public messaging framing operations as anti- Israeli solidarity-with-Palestinians hacktivism despite operational tradecraft remaining consistent with earlier Russia-aligned-targeting patterns) Operationally the cluster operated Skynet Stress Tester, a DDoS-for-hire commercial service apparently operating alongside hacktivism activity providing paid DDoS-attack capability to third-party customers in addition to cluster-selected hacktivism targeting. The Skynet Stress Tester operational model represents cluster monetization diversification beyond pure-hacktivism politically-motivated operations and is operationally distinctive among publicly-tracked hacktivism operations. The custom "Godzilla botnet" provided additional operational infrastructure alongside conventional DDoS tooling. A handful of operational notes: First, the cluster represents the central reference case for analyzing false-flag hacktivism operations. The combination of ostensibly-Sudanese branding with operationally Russia-aligned targeting and capability illustrates the analytical challenges of attributing contemporary hacktivism operations where operational claims and operational tradecraft do not align. Defender threat-modeling for contemporary hacktivism should treat self-claimed cluster identity as operationally distinct from analytically-attributable cluster origin. Second, the cluster represents one of the relatively few major contemporary hacktivism operations effectively terminated by Western law-enforcement action. The rapid disruption and named- individual attribution outcome (Ahmed Salah + Alaa Salah arrests March 2024) was operationally unusual for hacktivism operations , most contemporary hacktivism operations (Killnet, NoName057(16), and others) have remained operationally resilient despite sustained Western law-enforcement pressure because cluster administrators are protected by Russian jurisdiction. Anonymous Sudan's Sudanese-national operator base was operationally accessible to Western law-enforcement in ways that Russia-based cluster administrators are not. Third, the cluster's combination of hacktivism activity with DDoS-for-hire commercial operations (Skynet Stress Tester) represents an analytically interesting operational-doctrine data point about contemporary hacktivism cluster monetization diversification. The pattern suggests that hacktivism operations can blur into for-profit cybercrime, complicating clean analytical separation between hacktivism and cybercrime cluster categories. Fourth, the cluster's Microsoft 365 attack (June 2023) represents one of the most operationally consequential single hacktivism- attributed cyber operations in the publicly-tracked record. The attack demonstrated that contemporary hacktivism can produce operational service disruption at the major-cloud-provider scale previously associated with state-aligned APT operations. Defender threat-modeling for cloud-service providers should treat hacktivism-tier DDoS as meaningful threat category requiring substantial operational resilience engineering.

Aliases

16
anonymous sudananonymous_sudananonymoussudanskynet stress testerskynet_stress_testerskynetstresstestergodzilla botnetgodzilla_botnetgodzillabotnetstorm-1359storm 1359storm_1359infrashutdowninfra shutdowninfra_shutdowninfra_shut_down

Notable Campaigns

8
2024FBI Takedown and Indictment of Ahmed Salah and Alaa Salah (March 2024)
2024Post-Arrest Cluster Termination (March 2024 onward)
2023Anonymous Sudan Emergence (January 2023)
2023Scandinavian Airlines SAS Attack (February 2023)
2023Microsoft 365 + Outlook + OneDrive Service Disruption Attacks (June 2023)
2023X (Twitter) Attack (August 2023)
2023Cloudflare and Tumblr Attacks (October 2023)
2023Israeli Targeting During October 2023 Hamas-Israel War Period

Attribution & Reporting

Attributed by
FBI Cyber DivisionUS Department of JusticeUS Attorney's Office Central District of CaliforniaCISA (US Cybersecurity and Infrastructure Security Agency)HHS Health Sector Cybersecurity Coordination Center (HC3)UK National Cyber Security Centre (NCSC)Israeli National Cyber Directorate (INCD)Microsoft Threat Intelligence CenterCrowdStrikeMandiant / Google Cloud Threat IntelligenceRecorded Future Insikt GroupSentinelOneTrend MicroKaspersky GReATGroup-IBCheck Point ResearchTrellixIBM X-ForceRadwareCloudflareAkamaiFlashpointSearchlight CyberIntel 471TruesecCyberCXRecorded Future Insikt Group
Key reporting
reportUS DOJ US Attorney's Office Central District of California: Sudanese Nationals Charged in Anonymous Sudan Cyberattacks (October 16, 2024 unsealing, March 15, 2024 arrests), most operationally significant US-government formal action against cluster, indictments of Ahmed Salah Yousif Omer + Alaa Salah Yusuf Omer brothers
reportMicrosoft Threat Intelligence: Anonymous Sudan / Storm-1359 (June 16, 2023), Microsoft 365 attack disclosure
reportCloudflare: Anonymous Sudan DDoS Operational Analysis
reportCrowdStrike: Anonymous Sudan Pro-Russian DDoS Tracking
reportMandiant: Anonymous Sudan Attribution Analysis
reportRecorded Future Insikt Group: Anonymous Sudan Russia-Aligned Tracking
reportCheck Point Research: Anonymous Sudan Detailed Analysis
reportTruesec: Anonymous Sudan Deep Dive
reportAkamai: Anonymous Sudan Russia-Aligned Hacktivism Tracking
reportFlashpoint: Anonymous Sudan Tracking
reportSearchlight Cyber: Anonymous Sudan Storm-1359 Tracking
reportIsraeli National Cyber Directorate: Anonymous Sudan Operations During Israel-Hamas War Period
reportRadware: Anonymous Sudan DDoS Tracking
reportCyberCX: Anonymous Sudan Tracking
reportIntel 471: Anonymous Sudan Hacktivism Tracking
reportTrellix: Anonymous Sudan Continued Tracking
reportGroup-IB: Anonymous Sudan Continued Tracking
reportMalpedia Actor Profile: Anonymous Sudan

Operational

State sponsor

Anonymous Sudan is a hacktivism cluster of disputed origin, operationally publicly self-identifying as Sudanese hacktivism but Western analytical consensus widely treats Anonymous Sudan as a Russia-aligned operation using Sudanese identity as operational cover or false-flag rather than genuinely Sudanese hacktivism. The cluster has been active since approximately January 2023 with sustained operational tempo through March 2024 when FBI law-enforcement action effectively terminated cluster operations under that brand identity. The Sudanese-identity-as- false-flag analytical framing is supported by multiple operational-pattern data points: (1) the cluster's primary operational language and Telegram-channel coordination patterns align with Russia-speaking organized cyber operations rather than Sudanese-Arabic-speaking patterns, (2) operational targeting consistently aligns with Russian state foreign-policy interests (NATO-country government targeting, Western corporate technology targeting, opposition to Western sanctions on Russia) rather than Sudanese political interests, (3) cluster public messaging has explicitly endorsed Killnet and broader Russia-aligned hacktivism narratives, and (4) cluster operational sophistication and tooling capability substantially exceeds what would be operationally plausible for Sudanese hacktivism originating in a country with limited cybercrime infrastructure during a period of active civil war (April 2023+).

Modern Western vendor consensus (Microsoft Storm-1359 naming, CrowdStrike, Mandiant, Recorded Future, others) treats Anonymous Sudan as Russia-aligned despite the Sudanese-identity-marketing. The March 2024 FBI law-enforcement action complicates the analytical framing, FBI arrested and charged two Sudanese national brothers (Ahmed Salah Yousif Omer and Alaa Salah Yusuf Omer) as cluster operators, suggesting that while operational targeting and broader operational characteristics align with Russia-aligned hacktivism, at least some cluster operators were genuinely Sudanese individuals operating under apparent Russia-aligned operational coordination or financial sponsorship. The cluster operated Skynet Stress Tester (DDoS- for-hire commercial service apparently operating alongside hacktivism activity), with operational tooling including a custom "Godzilla botnet" alongside conventional DDoS infrastructure.

Motivations
hacktivism, apparent_false_flag_hacktivism_operations, apparent_russia_aligned_disruption_using_sudanese_identity_cover, politically_motivated_disruption, distributed_denial_of_service_operations, ddos_for_hire_commercial_operations, information_operations, religious_motivation_framing_messaging
Sectors
Regions

Detection Blind Spots

42 techniques
Across this actor’s 42 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)15/42 · 35%
Analytics (MITRE CAR)0/42 · 0%
Runtime / container (Falco)0/42 · 0%
File / malware (YARA)0/42 · 0%
Network (Suricata/Snort)6/42 · 14%
Vuln scan (Nuclei)0/42 · 0%

Atomic Test Plan

3 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SKYNET STRESS TESTER DDOS FOR HIRE SERVICE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin