Pro-Assad hacktivist collective aligned with (and widely assessed as at least tacitly supported by) the Syrian government of Bashar al-Assad. The group publicly surfaced under the umbrella of the Syrian Computer Society. US authorities named individual members in criminal charges; two indicted members (Ahmad Umar Agha and Firas Dardar) were placed on the FBI Cyber Most Wanted list. No formal state-agency attribution was established in court, and the group operated as a loosely organized collective rather than a proven government unit.
Origin
Syria
First seen
2011
Last active
2016
Motivation
Hacktivism / ideological — pro-Assad political messaging, retaliation against Western media and organizations perceived as hostile to the Syrian regime, plus some financially motivated extortion by individual members (per US charging documents).
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
SilverHawk and 2020 COVID-19-lure Android campaigns (Lookout) required victims to install trojanized app packages posing as security/messaging app updates and grant device-admin permissions.
Indictment lists website defacement as a primary follow-on action; defacements of media, government, and NGO sites with pro-Assad propaganda are SEA's signature hacktivist outcome.
Reached high-profile targets through third parties: Melbourne IT domain reseller (NYT/Twitter 2013) and Gigya/third-party web widget providers (Nov 2014 redirect of Forbes, Telegraph, CNBC and others), rather than the victim's own perimeter.
Indictment states the conspirators used stolen usernames and passwords from successful spearphishing to log in to victim web, email, and social media systems.
Credential-harvesting spearphish links pointed to cloned Google Apps / webmail login pages (The Onion, AP, Melbourne IT reseller) to collect employee credentials before any access was attempted.
Group registered look-alike phishing domains and hosted cloned login portals for its spearphishing campaigns (documented in the Onion, Melbourne IT and AP incidents).
Hijacked corporate Twitter/Facebook accounts (AP Twitter 2013 fake White House explosion tweet, Reuters, BBC, Guardian, Skype, Microsoft) using phished credentials and posted pro-Assad messaging.
Aug 2013 hijack of nytimes.com and twitter.com DNS records via compromised Melbourne IT reseller credentials, redirecting the domains to SEA-controlled hosts; indictment cites redirecting domains to conspiracy-controlled sites.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Syrian Electronic Army's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002significantApp GovernanceT1078significantApp GovernanceT1199significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1114significantAdvanced Threat HuntingT1199significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantDefender for Cloud AppsT1078partial
respond · 8 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1114significantAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1078minimalIncident ResponseT1566minimalIncident ResponseT1598.003minimalQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantQuarantine PoliciesT1566significant
Countermeasures · D3FEND
Defensive techniques that counter Syrian Electronic Army's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.