Pro-Palestinian / anti-Israel hacktivist collective that publicly presents as an independent group aligned with the Hamas 'Toufan Al-Aqsa' (Al-Aqsa Flood) framing. Multiple vendors (Check Point, Cybernews, SOCRadar, Recorded Future/The Record) assess a probable Iran nexus based on operational scale, timing, target selection, and wiper tradecraft, but the group has not confirmed its origins and the state-sponsorship link is an assessment, not a confirmed fact. Attribution should be treated as unconfirmed/medium-confidence for the Iran nexus and high-confidence only for the pro-Palestinian hacktivist positioning.
First seen
2023-11
Last active
2026-03
Motivation
Ideological/hacktivist and destructive: anti-Israel, pro-Palestinian retaliation tied to the Israel-Hamas war; hack-and-leak plus data destruction (wiping) rather than financial gain.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
OP Innovate: after obtaining an internal IP the actor systematically scanned the internal network to locate machines with exposed, unprotected SMB shares.
Beaumont (DoublePulsar, Jan 2024): the actor ran the legitimate shred utility via its own shell script designed to keep running if an administrator kills the process.
OP Innovate maps exfiltration to T1041: archives transferred over encrypted channels in coordinated multi-victim bursts (~16 GB from Signature-IT per Cyberint), with publication deliberately delayed.
Useful?
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
Cyberint: group claimed website defacements of Israeli companies alongside data breaches (single narrative source; lower confidence than the wiping/leak activity).
Beaumont/SecurityWeek: Linux servers wiped with shred for unrecoverable file deletion; the group claimed 1000+ servers and critical databases of 150+ victims destroyed; roughly a third of victims still offline weeks later.
Nov 16 2023 compromise of Israeli hosting/web provider Signature-IT (Check Point assessment via The Record) and an MSP (Beaumont) cascaded access to 100+ downstream customer organizations including Toyota Israel, Ikea Israel, ACE Hardware and government bodies.
OP Innovate's three confirmed intrusions found access via weak, reused or previously leaked credentials (infostealer logs, prior breaches, default third-party provider configs for Bezeq/Partner-managed devices) on accounts lacking MFA; no malware observed.
Cyberint/The Record/Wiz: hijacked victim email servers used to send 'The Cost of Complicity' threat emails to thousands of Israeli addresses and boycott-lobbying emails to victims' customers.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Cyber Toufan (Al-Aqsa)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 6 techniques
Defender for Cloud AppsT1133partialConditional AccessT1078minimalIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalPrivileged Identity ManagementT1078minimalPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1059minimalRole Based Access ControlT1078minimalRole Based Access ControlT1199partialAntimalwareT1059significantAntimalwareT1059.001significantAudit SolutionsT1078partialInformation ProtectionT1048significant
detect · 12 techniques
App GovernanceT1078significantApp GovernanceT1199significantAdvanced Threat HuntingT1048significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1199significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1485partialMicrosoft Defender for IdentityT1021minimalMicrosoft Defender for IdentityT1021.002minimalMicrosoft Defender for IdentityT1048minimalMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1059.001minimalMicrosoft Defender for Identity
respond · 4 techniques
Automated Investigation and ResponseT1048significantAutomated Investigation and ResponseT1078significantIncident ResponseT1059minimalIncident ResponseT1078minimalZero Hour Auto PurgeT1059significantZero Hour Auto PurgeT1059.001significantConditional AccessT1078minimal
Countermeasures · D3FEND
Defensive techniques that counter Cyber Toufan (Al-Aqsa)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.