The Syrian Electronic Army (SEA; ) was a group of
computer hackers which first surfaced online in 2011 to support the government of former
Syria
Syria, officially the Syrian Arab Republic, is a country in West Asia located in the Eastern Mediterranean and the Levant. It borders the Mediterranean Sea to the west, Turkey to Syria–Turkey border, the north, Iraq to Iraq–Syria border, t ...
n President
Bashar al-Assad. Using
spamming,
website defacement
Website defacement is an attack on a website that changes the visual appearance of a website or a web page. These are typically the work of hackers, who break into a web server and replace the hosted website with malware or a website of thei ...
,
malware
Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
,
phishing, and
denial-of-service attacks, it has targeted terrorist organizations, political opposition groups, western news outlets, human rights groups and websites that are seemingly neutral to the Syrian conflict. It has also hacked government websites in the
Middle East
The Middle East (term originally coined in English language) is a geopolitical region encompassing the Arabian Peninsula, the Levant, Turkey, Egypt, Iran, and Iraq.
The term came into widespread usage by the United Kingdom and western Eur ...
and Europe, as well as US defense contractors. , the SEA has been "the first Arab country to have a public Internet Army hosted on its national networks to openly launch
cyber attacks on its enemies".
The precise nature of SEA's relationship with the
Syrian government has changed over time and is unclear.
Origins and historical context
In the 1990s, Syrian President
Bashar al-Assad headed the
Syrian Computer Society, which is connected to the SEA, according to research by University of Toronto and University of Cambridge, UK.
[ There is evidence that a Syrian Malware Team goes as far back as January 1, 2011.]
In February 2011, after years of Internet censorship, Syrian censors lifted a ban on Facebook
Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
and YouTube
YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
.[ In April 2011, only days after anti-regime protests escalated in Syria, Syrian Electronic Army emerged on Facebook.][ On May 5, 2011 the Syrian Computer Society registered SEA’s website (syrian-es.com).][ Because Syria's domain registration authority registered the hacker site, some security experts have written that the group was supervised by the Syrian state. SEA claimed on its webpage to be no official entity, but "a group of enthusiastic Syrian youths who could not stay passive towards the massive distortion of facts about the recent uprising in Syria".]
As soon as May 27, 2011 SEA had removed text that denied it was an official entity.[ One commentator has noted that " EAvolunteers might include Syrian diaspora; some of their hacks have used colloquial English and ]Reddit
Reddit ( ) is an American Proprietary software, proprietary social news news aggregator, aggregation and Internet forum, forum Social media, social media platform. Registered users (commonly referred to as "redditors") submit content to the ...
memes. In July 2011, it emerged that Bashar al-Assad's page on Facebook page was run by a member of the Syrian Electronic Army close to the regime, Haidara Suleiman, the son of powerful intelligence officer and former Syrian ambassador in Amman, Bahjat Suleiman. He told AFP that "the official media is unfortunately weak... This is why we use electronic media to show people what's going on."
According to a 2014 report by security company Intelcrawler, SEA activity has shown links with "officials in Syria, Iran, Lebanon and Hezbollah." A February 2015 article by ''The New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'' stated that "American intelligence officials" suspect the SEA is "actually Iranian". However, no data has shown a link between Iran's and Syria's cyber attack patterns according to an analysis of "open-source intelligence
Open source intelligence (OSINT) is the collection and analysis of data gathered from open sources (overt sources and publicly available information) to produce actionable intelligence. OSINT is primarily used in national security, law enforceme ...
" by cyber security firm Recorded Future.
Online activities
SEA has pursued activities in three key areas:
*Website defacement
Website defacement is an attack on a website that changes the visual appearance of a website or a web page. These are typically the work of hackers, who break into a web server and replace the hosted website with malware or a website of thei ...
and electronic surveillance against Syrian rebels and other opposition: The SEA has carried out surveillance to discover the identities and location of Syrian rebels, using malware
Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
(including the Blackworm tool),[ phishing, and denial of service attacks. this electronic monitoring has extended to foreign aid workers.
*Defacement attacks against Western websites that it contends spread news hostile to the Syrian government: These have included news websites such as ]BBC News
BBC News is an operational business division of the British Broadcasting Corporation (BBC) responsible for the gathering and broadcasting of news and current affairs in the UK and around the world. The department is the world's largest broad ...
, the Associated Press
The Associated Press (AP) is an American not-for-profit organization, not-for-profit news agency headquartered in New York City.
Founded in 1846, it operates as a cooperative, unincorporated association, and produces news reports that are dist ...
, National Public Radio
National Public Radio (NPR) is an American public broadcasting organization headquartered in Washington, D.C., with its NPR West headquarters in Culver City, California. It serves as a national Radio syndication, syndicator to a network of more ...
, CBC News
CBC News is the division of the Canadian Broadcasting Corporation responsible for the news gathering and production of news programs on the corporation's English-language operations, namely CBC Television, CBC Radio, CBC News Network, and CBC ...
, Al Jazeera, ''Financial Times
The ''Financial Times'' (''FT'') is a British daily newspaper printed in broadsheet and also published digitally that focuses on business and economic Current affairs (news format), current affairs. Based in London, the paper is owned by a Jap ...
'', ''The Daily Telegraph
''The Daily Telegraph'', known online and elsewhere as ''The Telegraph'', is a British daily broadsheet conservative newspaper published in London by Telegraph Media Group and distributed in the United Kingdom and internationally. It was found ...
'', ''The Washington Post
''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
'', Syrian satellite broadcaster Orient TV, and Dubai-based al-Arabia TV,["Syrian Electronic Army: Disruptive Attacks and Hyped Targets"]
OpenNet Initiative, 25 June 2011 as well as rights organizations such as Human Rights Watch
Human Rights Watch (HRW) is an international non-governmental organization that conducts research and advocacy on human rights. Headquartered in New York City, the group investigates and reports on issues including War crime, war crimes, crim ...
. SEA targets include VoIP
Voice over Internet Protocol (VoIP), also known as IP telephony, is a set of technologies used primarily for voice communication sessions over Internet Protocol (IP) networks, such as the Internet. VoIP enables voice calls to be transmitted as ...
apps, such as Viber and Tango.
*Spamming popular Facebook pages with pro-regime comments: The Facebook pages of President Barack Obama
Barack Hussein Obama II (born August 4, 1961) is an American politician who was the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, he was the first African American president in American history. O ...
and former French President Nicolas Sarkozy have been targeted by such spam campaigns.[Sarah Fowle]
"Who is the Syrian Electronic Army?"
BBC News, 25 April 2013
*Global cyber espionage: "technology and media companies, allied military procurement officers, US defense contractors, and foreign attaches and embassies".
The SEA's tone and style vary from the serious and openly political to ironic statements intended as critical or pointed humor: SEA had "Exclusive: Terror is striking the #USA and #Obama is Shamelessly in Bed with Al-Qaeda" tweeted from the Twitter account of ''60 Minutes
''60 Minutes'' is an American television news magazine broadcast on the CBS television network. Debuting in 1968, the program was created by Don Hewitt and Bill Leonard, who distinguished it from other news programs by using a unique style o ...
'', and in July 2012 posted "Do you think Saudi and Qatar should keep funding armed gangs in Syria in order to topple the government? #Syria," from Al Jazeera's Twitter account before the message was removed. In another attack, members of SEA used the BBC Weather Channel Twitter account to post the headline, "Saudi weather station down due to head on-collision with camel." After ''Washington Post'' reporter Max Fisher called their jokes unfunny, one hacker associated with the group told a ''Vice
A vice is a practice, behaviour, Habit (psychology), habit or item generally considered morally wrong in the associated society. In more minor usage, vice can refer to a fault, a negative character trait, a defect, an infirmity, or a bad or unhe ...
'' interview 'haters gonna hate.'"[
]
Operating system
On 31 October 2014, the SEA released a Linux distribution
A Linux distribution, often abbreviated as distro, is an operating system that includes the Linux kernel for its kernel functionality. Although the name does not imply product distribution per se, a distro—if distributed on its own—is oft ...
named SEANux.
Timeline of notable attacks
2011
* July 2011: University of California Los Angeles website defaced by SEA hacker "The Pro".
* August 2011: Anonymous
Anonymous may refer to:
* Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown
** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author
* Anonym ...
-run social networking platform Anonplus is defaced. Citizen Lab attributes the attack to the Syrian Electronic Army.
* September 2011: Harvard University
Harvard University is a Private university, private Ivy League research university in Cambridge, Massachusetts, United States. Founded in 1636 and named for its first benefactor, the History of the Puritans in North America, Puritan clergyma ...
website defaced in what was called the work of a "sophisticated group or individual". The Harvard homepage was replaced with an image of Syrian president Bashar al-Assad with the message "Syrian Electronic Army Were Here".
2012
* April 2012: The official blog of social media website LinkedIn
LinkedIn () is an American business and employment-oriented Social networking service, social network. It was launched on May 5, 2003 by Reid Hoffman and Eric Ly. Since December 2016, LinkedIn has been a wholly owned subsidiary of Microsoft. ...
was redirected to a site supporting Bashar al-Assad.
* August 2012: The Twitter account of the Reuters
Reuters ( ) is a news agency owned by Thomson Reuters. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide writing in 16 languages. Reuters is one of the largest news agencies in the world.
The agency ...
news agency sent 22 tweets with false information on the conflict in Syria. The Reuters news website was compromised, and posted a false report about the conflict to a journalist's blog.
2013
* 20 April 2013: The Team Gamerfood homepage was defaced.["Team Gamerfood website defaced by SEA](_blank)
, ''TeamGamerfood.com'', 20 April 2013
* 23 April 2013: The Associated Press
The Associated Press (AP) is an American not-for-profit organization, not-for-profit news agency headquartered in New York City.
Founded in 1846, it operates as a cooperative, unincorporated association, and produces news reports that are dist ...
Twitter account falsely claimed the White House
The White House is the official residence and workplace of the president of the United States. Located at 1600 Pennsylvania Avenue Northwest (Washington, D.C.), NW in Washington, D.C., it has served as the residence of every U.S. president ...
had been bombed and President Barack Obama
Barack Hussein Obama II (born August 4, 1961) is an American politician who was the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, he was the first African American president in American history. O ...
injured. This led to a US$136.5 billion decline in value of the S&P 500
The Standard and Poor's 500, or simply the S&P 500, is a stock market index tracking the stock performance of 500 leading companies listed on stock exchanges in the United States. It is one of the most commonly followed equity indices and in ...
the same day.[Spillus, Ale]
"Who is the Syrian Electronic Army?"
''The Telegraph'', 24 April 2013
* May 2013: The Twitter account of '' The Onion'' was compromised by phishing Google Apps accounts of ''The Onion''s employees. The platform was also used by the hackers to spread pro-Syrian tweets.["How the Syrian Electronic Army Hacked The Onion](_blank)
, Tech Team, ''The Onion'', 8 May 2013
* 24 May 2013: The ITV News London Twitter account was hacked.
*On 26 May 2013: the Android applications of British broadcaster Sky News
Sky News is a British free-to-air television news channel, live stream news network and news organisation. Sky News is distributed via an English-language radio news service, and through online channels. It is owned by Sky Group, a division of ...
were hacked on Google Play Store.
* 17 July 2013: Truecaller servers were hacked into by the Syrian Electronic Army. The group claimed on its Twitter handle to have recovered 459 GiBs of database, primarily due to an older version of WordPress installed on the servers. The hackers released Truecaller's alleged database host ID, username, and password via another tweet. On 18 July 2013, TrueCaller confirmed on its blog that only their website was hacked, but claimed that the attack did not disclose any passwords or credit card information.
* 23 July 2013: Viber servers were hacked, the support website replaced with a message and a supposed screenshot of data that was obtained during the intrusion.[
* 15 August 2013: Advertising service Outbrain suffered a spearphishing attack and SEA placed redirects into the websites of The Washington Post, Time, and CNN.
* 27 August 2013: NYTimes.com had its DNS redirected to a page that displayed the message "Hacked by SEA" and Twitter's domain registrar was changed.
* 28 August 2013: Twitter's DNS registration showed the SEA as its Admin and Tech contacts, and some users reported that the site's Cascading Style Sheets (CSS) had been compromised.
* 29–30 August 2013: ''The New York Times'', ''The Huffington Post'', and Twitter were knocked down by the SEA. A person claiming to speak for the group stepped forward to tie these attacks to the increasing likelihood of U.S military action in response to al-Assad using chemical weapons. A self-described operative of the SEA told ABC News in an e-mail exchange: "When we hacked media we do not destroy the site but only publish on it if possible, or publish an article ]hat
A hat is a Headgear, head covering which is worn for various reasons, including protection against weather conditions, ceremonial reasons such as university graduation, religious reasons, safety, or as a fashion accessory. Hats which incorpor ...
contains the truth of what is happening in Syria. ... So if the USA launch attack on Syria we may use methods of causing harm, both for the U.S. economy or other."
* 2–3 September 2013: Pro-Syria hackers broke into the Internet recruiting site for the US Marine Corps, posting a message that urged US soldiers to refuse orders if Washington decides to launch a strike against the Syrian government. The site, www.marines.com, was paralyzed for several hours and redirected to a seven-sentence message "delivered by SEA".
* 30 September 2013: The Global Post's official Twitter account and website were hacked. SEA posted through their Twitter account, "Think twice before you publish untrusted informations '' ic' about Syrian Electronic Army" and "This time we hacked your website and your Twitter account, the next time you will start searching for new job"
* 28 October 2013: By gaining access to the Gmail account of an Organizing for Action staffer, the SEA altered shortened URLs on President Obama's Facebook and Twitter accounts to point to a 24-minute pro-government video on YouTube
YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
.
* 9 November 2013: SEA hacked the website of VICE, a no-affiliate news/documentary/blog website, which has filmed numerous times in Syria with the side of the Rebel forces. Logging into vice.com redirected to what appeared to be the SEA home page.
* 12 November 2013: SEA hacked the Facebook page of Matthew VanDyke, a Libyan Civil War veteran and pro-rebel news reporter.
2014
* 1 January 2014: SEA hacked Skype
Skype () was a proprietary telecommunications application operated by Skype Technologies, a division of Microsoft, best known for IP-based videotelephony, videoconferencing and voice calls. It also had instant messaging, file transfer, ...
's Facebook, Twitter and blog, posting an SEA related picture and telling users not to use Microsoft's e-mail service Outlook.com —formerly known as Hotmail—claiming that Microsoft sells user information to the government.
* 11 January 2014: SEA hacked the Xbox
Xbox is a video gaming brand that consists of four main home video game console lines, as well as application software, applications (games), the streaming media, streaming service Xbox Cloud Gaming, and online services such as the Xbox networ ...
Support Twitter pages and directed tweets to the group's website.
* 22 January 2014: SEA hacked the official Microsoft Office Blog, posting several images and tweeted about the attack.
* 23 January 2014: CNN's HURACAN CAMPEÓN 2014 official Twitter account showed two messages, including a photo of the Syrian Flag composed of binary code. CNN removed the Tweets within 10 minutes.
* 3 February 2014: SEA hacked the websites of eBay
eBay Inc. ( , often stylized as ebay) is an American multinational e-commerce company based in San Jose, California, that allows users to buy or view items via retail sales through online marketplaces and websites in 190 markets worldwide. ...
and PayPal UK. One source reported the hackers said it was just for show and that they took no data.
* 6 February 2014: SEA hacked the DNS of Facebook
Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
. Sources said the registrant contact details were restored and Facebook confirmed that no traffic to the website was hijacked, and that no users of the social network were affected.
* 14 February 2014: SEA hacked the Forbes
''Forbes'' () is an American business magazine founded by B. C. Forbes in 1917. It has been owned by the Hong Kong–based investment group Integrated Whale Media Investments since 2014. Its chairman and editor-in-chief is Steve Forbes. The co ...
website and their Twitter accounts.
* 26 April 2014: SEA hacked the information security
Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
-related RSA Conference website.
* 18 June 2014: SEA hacked the websites of British newspapers ''The Sun (United Kingdom)
''The Sun'' is a British Tabloid journalism, tabloid newspaper, published by the News UK#News Group Newspapers Ltd, News Group Newspapers division of News UK, itself a wholly owned subsidiary of Lachlan Murdoch's News Corp. It was founded a ...
'' and ''The Sunday Times
''The Sunday Times'' is a British Sunday newspaper whose circulation makes it the largest in Britain's quality press market category. It was founded in 1821 as ''The New Observer''. It is published by Times Newspapers Ltd, a subsidiary of N ...
''.
* 22 June 2014: The Reuters website was hacked a second time and showed a SEA message condemning Reuters for "publishing false articles about Syria". Hackers compromised the website, corrupting ads served by Taboola.
* 27 November 2014: SEA hacked hundreds of sites through hijacking Gigya
Gigya, Inc. was a technology company founded in Tel Aviv, Israel and headquartered in Mountain View, California, with additional offices in New York City, New York, Tel Aviv, London, Paris, Hamburg, and Sydney.
Gigya was purchased by SAP in 2017. ...
's comment system of prominent websites, displaying a message "You've been hacked by the Syrian Electronic Army(SEA)." Affected websites included the '' Aberdeen Evening Express'', Logitech, Forbes, ''The Independent
''The Independent'' is a British online newspaper. It was established in 1986 as a national morning printed paper. Nicknamed the ''Indy'', it began as a broadsheet and changed to tabloid format in 2003. The last printed edition was publis ...
'' UK Magazine, '' London Evening Standard'', '' The Telegraph'', NBC, the National Hockey League
The National Hockey League (NHL; , ''LNH'') is a professional ice hockey league in North America composed of 32 teams25 in the United States and 7 in Canada. The NHL is one of the major professional sports leagues in the United States and Cana ...
, Finishline.com, PCH.com, Time Out New York
''Time Out'' is a global magazine published by Time Out Group. ''Time Out'' started as a London-only publication in 1968 and has expanded its editorial recommendations to 333 cities in 59 countries worldwide.
In 2012, the London edition became ...
and t3.com (a tech website), stv.com, Walmart Canada, PacSun, '' Daily Mail'' websites, bikeradar.com (cycling website), SparkNotes, millionshort.com, Milenio.com, Mediotiempo.com, Todobebe.com and myrecipes.com, Biz Day SA, BDlive South Africa, muscleandfitness.com, and CBC News
CBC News is the division of the Canadian Broadcasting Corporation responsible for the news gathering and production of news programs on the corporation's English-language operations, namely CBC Television, CBC Radio, CBC News Network, and CBC ...
.
2015
* 21 January 2015: French newspaper ''Le Monde
(; ) is a mass media in France, French daily afternoon list of newspapers in France, newspaper. It is the main publication of Le Monde Group and reported an average print circulation, circulation of 480,000 copies per issue in 2022, including ...
'' wrote that SEA hackers "managed to infiltrate our publishing tool before launching a denial of service".
2018
*17 May 2018: Two suspects were indicted by the United States for "conspiracy" for hacking several US websites.
2021
* October 2021: Facebook
Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
discovers the presence of several fake accounts run by the SEA and its affiliated organizations. The accounts had reportedly been used to target Syrian opposition figures and human rights activists, as well as members of the YPG and White Helmets.
Legal actions
* 10 May 2016: Syrian Electronic Army member Peter Romar was extradited from Germany to the United States to face charges brought by the Department of Justice for engaging in a "a multi-year criminal conspiracy to conduct computer intrusions against perceived detractors of President Bashar al-Assad, including media entities, the White House and foreign governments."
* 28 September 2016: Peter Romar pled guilty to charges of helping the Syrian Electronic army extort cash from hacking victims.
See also
* Advanced persistent threat
* Hacktivism
* Internet censorship in Syria
* PLA Unit 61398
* Tailored Access Operations
References
External links
*
old account
Youtube Channel
Pinterest profile of the Syrian Electronic Army
VK profile of the Syrian Electronic Army
*
syrianelectronicarmy.com, first SEA website
which was later redirected to its .sy replacement
sea.sy
SEA's newer website, which SEA started in late May 2013; it has its access revoked by the Syrian Computer Society (site displays blank loading page on browser, and widget returns "ERROR 403: Forbidden" as of August 2013)
The Emergence of Open and Organized Pro-Government Cyber Attacks in the Middle East: The Case of the Syrian Electronic Army
Helmi Noman, May 30, 2011, published by Information Warfare Monitor, a public-private partnership between University of Ottawa and Secdev Group, including screenshots of SEA activities.
*
google cache of an SEA website
mentioned in Information Warfare Monitor report citing "syrian.es.sy" email ID as a contact address and links to a Facebook page named "Vict0r Battalion - Syrian Electronic Army". The page is no longer available starting from September 2013.
Understanding the Syrian Electronic Army (SEA)
HP-Security Research Blog
Syrian Cyber Hackers Charged - Two From ‘Syrian Electronic Army’ Added to Cyber’s Most Wanted
(FBI
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
)
{{Hacking in the 2010s
Organizations of the Syrian civil war
Paramilitary organizations based in Syria
Cyberwarfare
Hacker groups
Information operations and warfare
Propaganda organizations
Saboteurs
Propaganda in Syria