Anonymous Sudan
Anonymous Sudan (Skynet Stress Tester / Godzilla Botnet / Storm-1359 / InfraShutdown) is a hacktivism cluster of disputed origin, operationally publicly self-identifying as Sudanese hacktivism but Western analytical consensus widely treats Anonymous Sudan as a Russia-aligned operation using Sudanese identity as operational cover or false-flag rather than genuinely Sudanese hacktivism (supported by multiple operational-pattern data points: cluster operational language patterns aligning with Russia-speaking organized cyber operations rather than Sudanese- Arabic-speaking patterns, operational targeting consistently aligning with Russian state foreign-policy interests rather than Sudanese political interests, cluster public messaging explicitly endorsing Killnet and broader Russia-aligned hacktivism narratives, and cluster operational sophistication substantially exceeding what would be operationally plausible for Sudanese hacktivism originating in a country with limited cybercrime infrastructure during active civil war April 2023+)
active from approximately January 2023 through March 2024 when FBI law-enforcement action effectively terminated cluster operations under that brand identity.
most operationally consequential operation the June 2023 Microsoft 365 + Outlook + OneDrive sustained DDoS attacks producing operational service disruption for Microsoft 365 customers globally for multiple hours across multiple incident windows (Microsoft Storm-1359 attribution, demonstrating cluster operational capability to impact one of the most operationally resilient cloud-service providers globally)
other high-profile operations including Scandinavian Airlines SAS (February 2023), X (Twitter) (August 2023), Cloudflare and Tumblr (October 2023, operationally significant because Cloudflare is itself a major DDoS protection vendor), and Israeli targeting during October 2023 Hamas-Israel war period with public messaging framing operations as anti-Israeli solidarity-with-Palestinians hacktivism (operational tradecraft remaining consistent with earlier Russia-aligned-targeting patterns)
March 15 2024 FBI law-enforcement action (unsealed October 2024) arresting and indicting two Sudanese national brothers Ahmed Salah Yousif Omer (born ~1999) and Alaa Salah Yusuf Omer (born ~1996) as cluster operators with conspiracy to damage protected computers charges carrying maximum life imprisonment sentences, plus disruption of Skynet Stress Tester DDoS-for-hire commercial service operating alongside hacktivism activity, arrests complicating analytical framing of cluster origin (at least some cluster operators genuinely Sudanese individuals though operational targeting and characteristics align with Russia- aligned hacktivism, suggesting Russia-aligned operational coordination or financial sponsorship of Sudanese operators rather than direct Russian-operator cluster identity).