The Syrian Electronic Army (SEA) is a pro-Assad hacktivist group that emerged in 2011 during the early phase of the Syrian civil war. It became one of the most visible politically motivated hacking collectives of the 2011-2014 period, best known for hijacking the Twitter and other social-media accounts of major Western news organizations, defacing websites, and conducting phishing-driven credential theft against media outlets, human-rights groups, and US government-adjacent targets. Its signature incident was the April 2013 compromise of the Associated Press Twitter account, which pushed a false report of explosions at the White House injuring President Obama and briefly caused a sharp dip in US stock markets. The group's operational tempo declined after 2014, and it is now largely dormant.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
SEA appeared publicly around May 2011 as the Syrian uprising escalated, initially operating in association with the Syria-based Syrian Computer Society and using pro-regime messaging to counter online opposition to Bashar al-Assad. Rather than sophisticated custom malware, SEA relied on accessible, high-impact techniques: mass and spear-phishing to harvest credentials, social-engineering of media-organization staff, website defacements, and takeover of high-follower social-media accounts. In 2013 the group hijacked Twitter accounts belonging to the Associated Press, BBC, The Guardian, The Onion, the Financial Times, E! Online, and others; the April 23, 2013 AP hoax tweet claiming explosions at the White House briefly wiped roughly 130 billion USD off US equity markets before the AP confirmed the account had been compromised. In August 2013 SEA disrupted The New York Times and Twitter's domain records by phishing/compromising the reseller for registrar Melbourne IT, a DNS-hijacking-style redirection incident. Other 2013-2014 operations included defacement/redirect of the US Marine Corps recruiting site, phishing of CENTCOM-linked and White House staff, and compromises at Forbes, Microsoft, Skype, and Human Rights Watch. The US Department of Justice unsealed charges in March 2016 against Ahmad Umar Agha ('The Pro') and Firas Dardar ('The Shadow') for the spear-phishing and defacement campaigns, and against Dardar and Peter Romar for related extortion; Agha and Dardar were added to the FBI Cyber Most Wanted list with reward offers. Peter Romar was extradited and later pleaded guilty (2016-2018). Activity attributed to the core SEA declined sharply after 2014, and by 2016 onward the group is best characterized as dormant, with occasional low-confidence claims by successor or copycat personas. MENA relevance: Syria is SEA's HOME/ORIGIN nexus — the group is Syrian, pro-Assad, and rooted in the domestic information conflict of the Syrian civil war — NOT a victim geography. SEA's actual targets were overwhelmingly Western media, technology firms, human-rights organizations, and US government-adjacent entities; there is no substantial evidence of SEA targeting victims inside Syria or the broader MENA region. The Syria tag should therefore be read as attribution/origin, not victimology.