Anonymous Sudan
anonymous-sudan · primary source: Other · first observed 2022 · last observed 2024
?? · UnknownHacktivistHigh confidencelast cited Oct 15, 2024 · 1.6y ago
DDoS-as-a-service operation that publicly framed itself as Islamist hacktivism originating from Sudan; multiple researcher reports and the U.S. DOJ indictment unsealed in October 2024 identified two Sudanese nationals (the Omer brothers) as operators of the service from Sudan, not from Russia. Operated the 'Skynet' / 'InfraShutdown' DDoS service, briefly disrupted X (Twitter), Microsoft 365, and OpenAI services in 2023. Service disabled following the DOJ takedown.
Aliases
Storm-1359Microsoft
Motivations
disruptionfinancial gaininformation operations
Target sectors
technologygovernmentmediafinancialhealthcare
Target countries
USGBFRILSEDK
Diamond Model
Caltagirone / Pendergast / Betz 2013 — four-vertex attribution framework.
MITRE ATT&CK techniques
Timeline
1 eventIndicators of compromise
2 indicators| Type | Value | First seen | Source |
|---|---|---|---|
| Name | Primary Telegram handle/channel branding used by Anonymous Sudan to claim DDoS attacks (also operated companion bot @InfraShutdown_bot and channel 'Skynet/Godzilla-BotNet'). Documented verbatim throughout the DOJ indictment of the Omer brothers (Central District of California, March 2024, unsealed October 2024). | Jan 17, 2023 | U.S. Department of Justice |
| Name | family · DCAT Operator name for the Distributed Cloud Attack Tool (DCAT) used by Anonymous Sudan to launch 35,000+ DDoS attacks. Aliased as 'Skynet' and 'Godzilla Botnet' in the same Telegram channels. Tool seized and operators charged by DOJ in the unsealed October 2024 indictment of brothers Ahmed and Alaa Salah Yusuuf Omer. | Jan 17, 2023 | U.S. Department of Justice |
Related actors
shared ATT&CK techniques- UA · UkraineIT Army of Ukraine2 shared techniques
- RU · RussiaKillNet2 shared techniques
- RU · RussiaNoName057(16)2 shared techniques
References
cite this page
Threat Intel Tracker. (2026-05-19). Anonymous Sudan — actor profile. Retrieved from https://threatintel.local/actors/anonymous-sudan
latest cited activity · 2024-10-16 · 2 cataloged indicators