Attribution
Publicly self-presented as a Sudanese hacktivist group, but this persona is widely assessed by researchers (CyberCX, Trustwave, Microsoft, Amazon/AWS) to be misleading. The group aligned with and coordinated closely with the pro-Russia collective Killnet (from February 2023), used Russian-language infrastructure and Telegram tradecraft, and pursued Russian-aligned geopolitical targeting, leading several analysts to assess a probable Russia-nexus or Russian-directed/enabled operation. This assessment is contested: the March 2024 U.S. DOJ indictment named two Sudanese brothers as the actual operators, indicating that identifiable individuals of Sudanese nationality ran the group even as its cause and coordination leaned pro-Russian. Attribution of state sponsorship remains unproven; alignment with Killnet/pro-Russia hacktivism is well established.
Motivation
Hacktivism / ideological and geopolitical retaliation (framed around perceived anti-Islam and anti-Sudan grievances), pro-Russia political alignment, notoriety, and later financially motivated DDoS-for-hire via its InfraShutdown service.