Also known as: People's Cyber Army, Cyber Av3ngers, Storm-0784, DarkStorm, MRHELL112, INC Ransomware, the Handala Hack Team, Storm-0842, Banished Kitten, Temp Zagros, Static Kitten, 313 Team, the 313 Team, Islamic Cyber Resistance
RipperSec emerged in mid‑2023 as an openly political hacktivist group that aligns its public posturing with pro‑Palestinian sentiment. Its attack surface traditionally comprised publicly accessible web applications and portals hosted by governments, educational institutions, and commercial enterprises – where it orchestrated high‑volume DDoS using the MegaMedusa tool, defaced websites for propaganda purposes, and leaked stolen data through Telegram channels. In recent campaigns the group has broadened its threat horizon to include industrial control systems (ICS). Reports from Unit 42 show a dedicated sub‑team – branded Cyber Av3ngers or CL‑STA‑1128 – targeting Rockwell Automation and Allen‑Bradley PLCs. They employ AI‑driven spear‑phishing to harvest privileged credentials, subsequently performing lateral movement across corporate networks and executing remote factory resets via hijacked Intune sessions. Custom wiper payloads (Hatef for Windows, Hamsa for Linux) are delivered through multi‑stage loaders and the infostealer Rhadamanthys is also observed. The collective’s operations indicate a tactical shift from purely public‐facade disruption to more invasive infrastructure sabotage, underscoring an increased capacity to blend opportunistic attacks with targeted, politically motivated campaigns. Despite this evolution, RipperSec relies heavily on community participation and publicly available tools rather than specialized hardware or sophisticated custom malware. Overall, RipperSec’s activities illustrate a modern hacktivist threat model that combines low‑cost, high‑visibility tactics with escalating industrial sabotage capabilities to influence geopolitical narratives while destabilizing critical services.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
RipperSec is a pro‑Palestinian hacktivist collective that mounts public web DDoS campaigns, defacements and data leaks while targeting government, educational, industrial control and critical infrastructure sites perceived to support Israel or the United States. Their operations leverage readily available tools such as MegaMedusa for DDoS, AI‑enhanced phishing, and custom wiper malware (Hatef/Hamsa) to disrupt services and compromise remote management systems like Microsoft Intune. The group has expanded from web attacks into OT/ICS environments, exploiting PLC vulnerabilities and enabling remote factory resets.
Goals & Targeting
RipperSec’s strategic objective is primarily political disruption – to cast a negative light on Israel and its allies by exposing vulnerabilities in government and commercial systems. The group targets institutions that symbolically represent state authority, technological progress or economic stability: ministries, universities, energy suppliers, telecommunications providers, OT/ICS manufacturers, and global corporations with Israeli ties. Their targeting profile is broad yet purposeful; they choose high‑profile entities for maximum visibility while also striking industrial assets to demonstrate tangible harm. By leveraging community-based operations and open-source tools, they lower operational barriers, enabling rapid deployment of campaigns aligned with current geopolitical events.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Historically, RipperSec has executed synchronized, high‑profile DDoS bursts (e.g., attacks against Australian Moodle instances) timed with the Iran–Israel–US conflict to maximize propaganda impact. The group demonstrates a rapid operational tempo, announcing campaign windows via Telegram and other social channels and then deploying attack vectors almost immediately. Victim types span from public sector web portals to commercial e‑learning platforms and, more recently, industrial control stations. Notable past operations include the MegaMedusa‑driven DDoS against propeller‑drones.com, a defacement campaign on a UAE government site, and a sabotage push targeting Rockwell Automation PLCs marked by remote factory resets. The pattern suggests an evolving strategy that blends opportunistic public attacks with more targeted infrastructure strikes as part of a broader political agenda.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core attribution of RipperSec’s public DDoS and defacement activities is high, supported by multiple independent threat reports citing MegaMedusa usage and Telegram coordination. Confidence regarding their recent OT/ICS targeting remains moderate; it is largely based on third‑party analyses describing tactics and target selection but lacks direct evidence such as signed malicious code or confirmed infrastructure. Key information gaps include the group’s definitive leadership, precise operational timelines (first seen/last seen), full technical stack for remote factory reset exploits, and a comprehensive list of affected industrial control systems.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics