Home/Threat Actor/SiegedSec
Threat Actor

SiegedSec

siegedsec · international_hacktivist_collective · active since 2022-02

SiegedSec was a hacktivist collective publicly active from February 2022 through July 2024 (formal disbandment following OpNATO operation against NATO Communities of Interest Cooperation Portal) self-described as "gay furry hackers" with progressive political ideology motivations including LGBTQ+ rights advocacy, anti-anti-trans-legislation activism, and climate activism, operationally distinctive in the hacktivist ecosystem for its progressive-political positioning (versus the broader hacktivist ecosystem's predominantly anti-Western state-aligned or Islamist alignment patterns) and embedded LGBTQ+ identity in operational messaging; signature tradecraft was opportunistic web application vulnerability exploitation (SQL injection, XSS, IDOR) against target organizational infrastructure resulting in data exfiltration for public leak publication via Telegram and Twitter/X, smash-and-grab operations rather than long-dwell espionage, no custom malware, no financial extortion; operational history includes OpTransRights US state government targeting (2023, Texas, Florida, South Carolina, Tennessee, Kentucky, Nebraska), Heineken corporate targeting (2023), Idaho National Laboratory and climate-activism-motivated oil and gas sector operations, culminating in the July 2024 OpNATO operation (approximately 900 NATO documents leaked) followed by formal disbandment announcement citing law- enforcement attention.

operationally distinct from all other hacktivist collectives curated in this corpus (Anonymous Sudan, KillNet, NoName057(16), GhostSec, Cyber Partisans, IT Army of Ukraine, CyberAv3ngers, Predatory Sparrow).

international_hacktivist_collective confidence: high 9 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

SiegedSec (self-designated, also "Sieged Security," sometimes self-describing as "gay furry hackers") was a financially- not-motivated hacktivist collective publicly active from approximately February 2022 through July 2024, when the collective formally announced its disbandment following the OpNATO operation against the NATO Communities of Interest Cooperation Portal. The collective was operationally distinctive within the hacktivist ecosystem in three dimensions: (1) PROGRESSIVE-POLITICAL-IDEOLOGY OPERATIONAL MISSION. SiegedSec self-described as ideologically motivated by progressive political causes including LGBTQ+ rights advocacy, anti-anti-trans-legislation activism, climate activism, and selective anti-government operations. The political- ideological positioning operationally distinguished SiegedSec from the broader hacktivist ecosystem where most clusters align with anti-Western state-aligned ideological positions (KillNet, NoName057(16), Russian-aligned), Islamist political positioning (Anonymous Sudan, Ghost Sec), or pro-Western state- aligned positioning (Cyber Partisans, IT Army of Ukraine). SiegedSec's progressive-political positioning was operationally and ideologically distinct from these alignment patterns. (2) LGBTQ+ IDENTITY EMBEDDED IN OPERATIONAL MESSAGING. The collective publicly embedded LGBTQ+ identity and culture in its public-facing operational messaging, including the collective's self-description as "gay furry hackers" used in operational claims and Telegram channel branding, and a public-facing operational tone combining political messaging with internet-subculture humor. The operational culture positioning was operationally distinctive in the hacktivist ecosystem and generated significant media attention. (3) FINITE OPERATIONAL LIFECYCLE WITH FORMAL DISBANDMENT. The collective operated for approximately two and a half years before formally announcing disbandment in July 2024 following the OpNATO operation, citing accumulating law- enforcement attention. The formal disbandment is operationally distinctive in the hacktivist ecosystem where most clusters either continue operations indefinitely or operationally degrade without formal closure announcements. The collective's signature operational tradecraft was opportunistic web application vulnerability exploitation (SQL injection, cross-site scripting, web application vulnerabilities) against target organizational web infrastructure resulting in data exfiltration for public leak publication via Telegram channels, Twitter/X, and dark-web data publication platforms, operationally smash-and-grab tradecraft rather than long-dwell espionage. The collective did not deploy custom malware, did not conduct sustained network persistence operations, and did not pursue financial extortion, operationally distinguishing its tradecraft from the cybercriminal ransomware ecosystem and from state-aligned cyber espionage clusters. The operational tradecraft level was assessed as commodity-tier rather than state-aligned-sophisticated. The collective's tracked operational history included: OpTransRights (2023, sustained operations against US state governments with anti-trans legislation, including Texas, Florida, South Carolina, Tennessee, Kentucky, Nebraska); Heineken corporate targeting (2023)

climate-activism- motivated oil-and-gas sector targeting including the Idaho National Laboratory operation (June 2023)

selective additional corporate and government operations.

and the culminating OpNATO operation (July 2024) resulting in the publication of approximately 900 NATO Communities of Interest Cooperation Portal documents and user account information. SiegedSec is operationally distinct from all other hacktivist collectives curated in this corpus, Anonymous Sudan (anonymous_sudan.yaml, Russian-aligned Islamist DDoS), KillNet (killnet.yaml, Russian-aligned pro-Kremlin), NoName057(16) (noname057_16.yaml, Russian-aligned anti-Ukrainian DDoS), GhostSec (ghostsec.yaml, Islamist-targeting), Cyber Partisans (cyber_partisans.yaml, Belarusian-democratic), IT Army of Ukraine (it_army_ukraine.yaml, pro-Ukrainian), CyberAv3ngers (cyberav3ngers.yaml, Iran-aligned OT-targeting), and Predatory Sparrow (predatory_sparrow.yaml, Israel-aligned, suspected state-coordinated). SiegedSec's progressive-political-ideology positioning fills a distinct cell in this curated hacktivism coverage.

Aliases

9
siegedsecsiegedsecsieged securitygay furry hackerssiegedsec gay furry hackersoptransrightsopnatosieged_secsieged sec

Notable Campaigns

5
2024OpNATO, NATO Communities of Interest Cooperation Portal Leak and Disbandment (July 2024)
2023-2024Climate Activism-Motivated Oil and Gas Sector Targeting
2023OpTransRights, US State Government Targeting Following Anti-Trans Legislation (2023)
2023Heineken Corporate Targeting (2023)
2022-2024Telegram-Centric Operational Culture and Public Identity Positioning

Attribution & Reporting

Attributed by
Recorded Future Insikt GroupMandiant (Google Threat Intelligence)SOCRadarReuters investigative reportingWired magazineBleepingComputerThe Record (Recorded Future Media)NATO Communications and Information Agency (NCI Agency)US Federal Bureau of Investigation (FBI)SentinelOne
Key reporting
reportRecorded Future Insikt Group: SiegedSec Hacktivist Collective Operational Tracking
reportMandiant / Google Threat Intelligence: SiegedSec Hacktivist Operations Analysis
reportSOCRadar: SiegedSec Dark Web Profile
reportReuters Investigative Reporting: SiegedSec Hacker Group Disbands After NATO Leak (July 2024)
reportWired Magazine: SiegedSec NATO Leak Coverage (July 2024)
reportBleepingComputer: SiegedSec Operational Coverage Multiple 2023-2024 Articles
reportThe Record (Recorded Future Media): SiegedSec Investigative Coverage
reportNATO Communications and Information Agency Public Statement on Communities of Interest Portal Incident
reportMalpedia Actor Profile: SiegedSec

Operational

State sponsor

SiegedSec was a financially-not-motivated hacktivist collective publicly active from approximately February 2022 through July 2024, a group that self-described as ideologically motivated by progressive political causes including LGBTQ+ rights advocacy, anti-anti-trans-legislation activism, climate activism, and selective anti-government operations. The collective publicly self-described as "gay furry hackers" and embedded LGBTQ+ identity and culture in its public-facing operational messaging, operationally distinctive in the hacktivist ecosystem where most clusters do not embed identity-based self-presentation in operational messaging. The collective was assessed by industry analysis (Recorded Future, Mandiant, SOCRadar, Reuters investigative reporting) as a non-state-sponsored hacktivist collective with international membership but no known state sponsorship, government affiliation, or commercial cybercriminal motivation.

The collective's operations were ideologically- motivated rather than financially-motivated, no ransom demands, no data sales to cybercriminal markets, and operational disclosure messaging consistently emphasized ideological objectives. The collective is curated as a distinct cluster from other hacktivist operations in this corpus, Anonymous Sudan (anonymous_sudan.yaml), KillNet (killnet.yaml), NoName057(16) (noname057_16.yaml), GhostSec (ghostsec.yaml), Cyber Partisans (cyber_partisans.yaml), IT Army of Ukraine (it_army_ukraine.yaml), and the Cyber Av3ngers (cyberav3ngers.yaml), based on its distinct operational mission, ideological positioning, victim targeting profile, and operational structure. SiegedSec formally announced its disbandment on July 11, 2024 following the OpNATO operation that resulted in the leak of NATO Communities of Interest Cooperation Portal data, stating in the disbandment announcement that the collective was concluding operations to avoid law enforcement attention.

Motivations
hacktivism, lgbtq_rights_advocacy, anti_anti_trans_legislation_activism, climate_activism, selective_anti_government_operations, data_leak_as_political_statement, ideological_political_messaging, reputational_damage_to_targeted_entities
Sectors
Regions

Detection Blind Spots

44 techniques
Across this actor’s 44 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)32/44 · 72%
Analytics (MITRE CAR)11/44 · 25%
Runtime / container (Falco)10/44 · 22%
File / malware (YARA)1/44 · 2%
Network (Suricata/Snort)14/44 · 31%
Vuln scan (Nuclei)0/44 · 0%

Atomic Test Plan

21 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZ FILE HOSTINGMETASPLOITSQL INJECTION TOOLS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin