threatintel
actor tracker
All actors

Anonymous Sudan

anonymous-sudan · primary source: Other · first observed 2022 · last observed 2024
?? · UnknownHacktivistHigh confidencelast cited Oct 15, 2024 · 1.6y ago

DDoS-as-a-service operation that publicly framed itself as Islamist hacktivism originating from Sudan; multiple researcher reports and the U.S. DOJ indictment unsealed in October 2024 identified two Sudanese nationals (the Omer brothers) as operators of the service from Sudan, not from Russia. Operated the 'Skynet' / 'InfraShutdown' DDoS service, briefly disrupted X (Twitter), Microsoft 365, and OpenAI services in 2023. Service disabled following the DOJ takedown.

Aliases

Storm-1359Microsoft

Motivations

disruptionfinancial gaininformation operations

Target sectors

technologygovernmentmediafinancialhealthcare

Target countries

USGBFRILSEDK

Diamond Model

Caltagirone / Pendergast / Betz 2013 — four-vertex attribution framework.

Adversary
  • Anonymous Sudan
  • Unknown
  • disruption
  • financial gain
  • information operations
Capability
Infrastructure
Victim
  • technology
  • government
  • media
  • US
  • GB
  • +1 more

MITRE ATT&CK techniques

Timeline

1 event

Indicators of compromise

2 indicators
csv
TypeValueFirst seenSource
Name
@InfraShutdown
Primary Telegram handle/channel branding used by Anonymous Sudan to claim DDoS attacks (also operated companion bot @InfraShutdown_bot and channel 'Skynet/Godzilla-BotNet'). Documented verbatim throughout the DOJ indictment of the Omer brothers (Central District of California, March 2024, unsealed October 2024).
Jan 17, 2023U.S. Department of Justice
Name
InfraShutdown
family · DCAT
Operator name for the Distributed Cloud Attack Tool (DCAT) used by Anonymous Sudan to launch 35,000+ DDoS attacks. Aliased as 'Skynet' and 'Godzilla Botnet' in the same Telegram channels. Tool seized and operators charged by DOJ in the unsealed October 2024 indictment of brothers Ahmed and Alaa Salah Yusuuf Omer.
Jan 17, 2023U.S. Department of Justice

Related actors

shared ATT&CK techniques

References

cite this page

Threat Intel Tracker. (2026-05-19). Anonymous Sudan — actor profile. Retrieved from https://threatintel.local/actors/anonymous-sudan

latest cited activity · 2024-10-16 · 2 cataloged indicators