Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1090 ↗inferred | Proxy | Command and Control | Microsoft: use of open proxies; Cloudflare: cloud servers relay commands to 'open proxy resolvers' that transmit attack traffic, plus paid proxies, to randomize and conceal the source. |
| T1499.003 ↗inferred | Application Exhaustion Flood | Impact | Microsoft: 'cache bypass' queries forcing requests to origin servers; Cloudflare: deliberate targeting of 'high-cost endpoints' and multiple subdomains at low RPS to evade thresholds. |
| T1499 ↗inferred | Endpoint Denial of Service | Impact | Microsoft MSRC (Storm-1359, June 2023): Layer 7 DDoS against Outlook.com, OneDrive and Azure Portal exhausting backend resources rather than bandwidth. |
| T1499.002 ↗inferred | Service Exhaustion Flood | Impact | Microsoft: HTTP(S) floods of SSL/TLS handshakes and HTTP(S) requests plus Slowloris slow-connection attacks; Cloudflare: thousands of HTTP GET requests from thousands of unique IPs. |
| T1657 ↗inferred | Financial Theft | Impact | Cloudflare and DOJ: DDoS-for-hire sales plus extortion campaigns demanding ransom payments from victims to stop attacks. |
| T1498 ↗inferred | Network Denial of Service | Impact | DOJ 2024 indictment: DCAT ('Godzilla'/'Skynet'/'InfraShutdown') used for 35,000+ DDoS attacks incl. Cedars-Sinai ED outage; core capability of the actor. |
| T1498.001 ↗inferred | Direct Network Flood | Impact | Cloudflare LameDuck report: multi-vector attacks combining 'TCP-based direct-path' floods with L7 floods. |
| T1498.002 ↗inferred | Reflection Amplification | Impact | Cloudflare LameDuck report: attacks used 'various UDP reflection or amplification vectors' alongside direct-path traffic. |
| T1594 ↗inferred | Search Victim-Owned Websites | Reconnaissance | Cloudflare LameDuck report: operators identified victim 'high-cost endpoints', multiple interfaces/subdomains and 'high-demand periods' before striking to maximize disruption. |
| T1583.003 ↗inferred | Virtual Private Server | Resource Development | Microsoft assessed Storm-1359 relies on access to multiple VPS; Cloudflare: 'rented servers — which can output more traffic than personal devices' instead of a traditional botnet. |
| T1587 ↗inferred | Develop Capabilities | Resource Development | DOJ indictment: the Omer brothers developed and operated the DCAT DDoS tool (seized by FBI March 2024) and sold access to 100+ DDoS-for-hire customers. |
| T1583.006 ↗inferred | Web Services | Resource Development | Microsoft: attacks rely on 'rented cloud infrastructure'; DOJ/Cloudflare: DCAT = Distributed Cloud Attack Tool built on cloud-based servers forwarding commands to attack nodes. |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Anonymous Sudan's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Anonymous Sudan's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.