Anonymous Sudan was a prolific DDoS hacktivist group that emerged in January 2023 and, over roughly 15 months, launched tens of thousands of distributed-denial-of-service attacks against high-profile targets worldwide before being disrupted by U.S. law enforcement in March 2024. Microsoft tracks the actor as Storm-1359. The group operated a powerful custom Layer 7 DDoS toolkit and cloud-based Distributed Cloud Attack Tool (DCAT) infrastructure (branded internally as 'Godzilla'/'Skynet' and sold as the 'InfraShutdown' DDoS-for-hire service), which it used to knock over globally significant services including Microsoft cloud (Azure/Outlook/OneDrive), OpenAI's ChatGPT, X (Twitter), Telegram, hospitals, and government agencies.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Anonymous Sudan first appeared around 15 January 2023, branding itself as a Sudanese hacktivist collective retaliating against perceived anti-Muslim and anti-Sudanese activity in the West. Within weeks (February 2023) it publicly affiliated with the pro-Russia hacktivist collective Killnet, and its target selection, Russian-language coordination, and tradecraft led CyberCX, Trustwave and others to assess the 'Sudanese hacktivist' identity as a likely cover for a Russia-aligned (possibly Russia-directed) influence-and-disruption operation designed to stir Western societal division. Through 2023 it conducted sustained Layer 7 HTTP(S) flood campaigns, most notably a June 2023 wave that caused visible outages across Microsoft 365 and Azure portals (Microsoft's Storm-1359 disclosure). It went on to disrupt OpenAI's ChatGPT, X (Twitter), Telegram, PayPal, airlines, hospitals such as Cedars-Sinai, and numerous government sites. Technically, the group ran a rented cloud-hosted Distributed Cloud Attack Tool (DCAT) known internally as 'Godzilla'/'Skynet' and marketed to third parties as the paid 'InfraShutdown' DDoS-for-hire service, capable of large, sustained application-layer floods. On 16 October 2024 the U.S. DOJ unsealed a Central District of California indictment (filed March 2024) charging two Sudanese brothers, Ahmed Salah Yousif Omer (22) and Alaa Salah Yusuuf Omer (27), with running Anonymous Sudan; Ahmed Salah faced charges carrying a statutory maximum of life imprisonment. In March 2024 the U.S. seized and disabled the group's key DCAT/InfraShutdown components, and the group has been effectively disrupted and inactive since. Note on tooling names: 'Skynet' here refers to Anonymous Sudan's DDoS tool and should not be confused with unrelated malware/botnets sharing that name. MENA relevance: MIXED. Anonymous Sudan genuinely conducted DDoS waves against Israeli targets (e.g., claimed attacks on Israeli infrastructure and websites during 2023, including around the September 2023 and later periods), so the Israel tag reflects real, corroborated targeting. Its self-declared Sudanese origin is supported by the DOJ indictment, giving MENA a real operational nexus. The UAE and Iran country tags on the RaqibCTI record are far weaker: Gulf/UAE targeting rests largely on the group's own Telegram claims with limited independent corroboration (treat as unverified/opportunistic hacktivist claims), and Iran targeting is thin and not well substantiated in authoritative reporting — Anonymous Sudan's pro-Russia alignment sat alongside, not against, Iran-aligned hacktivism. Verdict: keep Israel (real); downgrade UAE to unverified/claim-only; Iran is thinly supported and should be reviewed or removed absent corroborating sourcing.