Anonymous Sudan is a hacker group that has been active since mid-January 2023 and believed to have originated from
Russia with no links to Sudan or
Anonymous
Anonymous may refer to:
* Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown
** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author
* Anonym ...
.
They have launched a variety of
distributed denial-of-service (DDoS) attacks against targets.
Origins and identity
Despite the name, there is no proven link between Anonymous Sudan and the country of
Sudan
Sudan ( or ; ar, السودان, as-Sūdān, officially the Republic of the Sudan ( ar, جمهورية السودان, link=no, Jumhūriyyat as-Sūdān), is a country in Northeast Africa. It shares borders with the Central African Republic t ...
.
The group surfaced as a Russian-speaking
Telegram channel in mid-January. Some experts, including cybersecurity company
CyberCX,
believe the group originates from or is supported by Russia.
The group is also not linked to
Anonymous
Anonymous may refer to:
* Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown
** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author
* Anonym ...
.
Targets and motives
Anonymous Sudan claims to target countries and organizations engaging in self-described "anti-Muslim activity".
The group claims to be
anti-Zionist
Anti-Zionism is opposition to Zionism. Although anti-Zionism is a heterogeneous phenomenon, all its proponents agree that the creation of the modern State of Israel, and the movement to create a sovereign Jewish state in the region of Palestine ...
and pro-Islam. However, they have also collaborated with pro-Russian attack groups like
Killnet, and their attacks seem to align with a pro-Russian agenda.
As a response to the
International Committee of the Red Cross rules of engagement for civilian hackers, a representative of Anonymous Sudan said these rules were "not viable and that breaking them for the group's cause is unavoidable".
Attacks
Anonymous Sudan has launched a variety of
distributed denial-of-service (DDoS) attacks against targets in Sweden, Denmark, the US, Australia, and other countries.
Their victims include
Cloudflare,
Associated Press,
Netflix, and
PayPal, among others. Anonymous Sudan has successfully disrupted the website of
Scandinavian Airlines
Scandinavian Airlines, more commonly known and styled as SAS, is the flag carrier of Denmark, Norway, and Sweden. ''SAS'' is an abbreviation of the company's full name, Scandinavian Airlines System or legally Scandinavian Airlines System Denmark ...
(SAS) and even took down
Microsoft 365 software suite, including
Teams and
Outlook.
They also took
Twitter (now known as X) offline in more than a dozen countries to pressure
Elon Musk to enable
Starlink service for Sudan.
According to the Cyberint Research Team, the group launched 670 attacks in their first 6 months of activity.
On 8 June 2023, Anonymous Sudan claimed responsibility for a DDoS attack on
Azure
Azure may refer to:
Colour
* Azure (color), a hue of blue
** Azure (heraldry)
** Shades of azure, shades and variations
Arts and media
* ''Azure'' (Art Farmer and Fritz Pauer album), 1987
* Azure (Gary Peacock and Marilyn Crispell album), 2013
...
portal which caused an outage of this and other Microsoft cloud services between ~15 UTC and ~17:30 UTC.
During the
War in Sudan between the
Sudanese Armed Forces (SAF) and
Rapid Support Forces (RSF), Anonymous Sudan launched cyberattacks on the
Kenyan government and private websites in the last week of July 2023, in retaliation for the country's support of the RSF. In January and February 2024, Anonymous Sudan claimed to have disabled all internet services in Chad and Djibouti, respectively, as part of a cyberattack to protest the country's relations with the RSF. The group continued attacking
Intergovernmental Authority on Development (IGAD) countries (including Uganda in February) due to their backing of the RSF. The group also attacked the United Arab Emirates, a major supporter of the RSF.
On 10 July 2023, Anonymous Sudan attacked fanfiction site
Archive of Our Own
Archive of Our Own (often shortened to AO3) is a nonprofit open source repository for fanfiction and other fanworks contributed by users. The site was created in 2008 by the Organization for Transformative Works and went into open beta in 2009. ...
with a
denial-of-service attack. Anonymous Sudan claimed responsibility in a
Telegram post, saying the act was motivated by the website's United States registration and its inclusion of sexual and
LGBT content.
The group then demanded $30,000 worth of
Bitcoin
Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
within 24 hours to end the attack.
The site came back online the next day with
Cloudflare protection added.
During the
Israel–Hamas war, media teams operating in the region have been exposed to various kinds of cyberattack. The ''
Jerusalem Post
''The Jerusalem Post'' is a broadsheet newspaper based in Jerusalem, founded in 1932 during the British Mandate of Palestine by Gershon Agron as ''The Palestine Post''. In 1950, it changed its name to ''The Jerusalem Post''. In 2004, the paper w ...
'' website went down on 9 October 2023, with Anonymous Sudan claiming responsibility. The Palestinian Authority news agency
Wafa also experienced a cyberattack on 18 October 2023, as did
Al-Jazeera English
Al Jazeera English (AJE; ar, الجزيرة, translit=al-jazīrah, , literally "The Peninsula", referring to the Qatar Peninsula) is an international 24-hour English-language news channel owned by the Al Jazeera Media Network, which is own ...
on 31 October 2023 and
Al-Mamlaka TV on 3 November 2023.
In November 2023, the group targeted Israel infrastructure.
In December 2023, Anonymous Sudan launched a
DDoS
In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host
A ...
attack on
ChatGPT after Tal Broda, a member of
OpenAI's leadership, made a social media post
dehumanizing
Dehumanization is the denial of full humanness in others and the cruelty and suffering that accompanies it. A practical definition refers to it as the viewing and treatment of other persons as though they lack the mental capacities that are c ...
Palestinians, calling for more intense bombing in Gaza, and advocating
ethnic cleansing
Ethnic cleansing is the systematic forced removal of ethnic, racial, and religious groups from a given area, with the intent of making a region ethnically homogeneous. Along with direct removal, extermination, deportation or population transfer ...
.
In January 2024, Anonymous Sudan failed to hack the
London Internet Exchange
The London Internet Exchange ("LINX") is a mutually governed Internet exchange point (IXP) that provides peering services and public policy representation to network operators (over 950 different ASNs). It was founded in 1994 in London. LI ...
in response to the
UK's missile strikes in Yemen.
The group targeted systems at the
University of Cambridge and the
University of Manchester on 19 February 2024, citing the United Kingdom's support for
Israel in the Israel–Hamas War, and targeting these specific universities "because they are the biggest ones" they could find. Disruption was largely over by 20 February though some systems were still affected.
References
{{Hacking in the 2020s
Hacker groups
Hacking in the 2000s
Hacktivists
Hacking in the 2020s
Cyberattack gangs