Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RipperSec

Also known as: People's Cyber Army, Cyber Av3ngers, Storm-0784, DarkStorm, MRHELL112, INC Ransomware, the Handala Hack Team, Storm-0842, Banished Kitten, Temp Zagros, Static Kitten, 313 Team, the 313 Team, Islamic Cyber Resistance

Description

RipperSec emerged in mid‑2023 as an openly political hacktivist group that aligns its public posturing with pro‑Palestinian sentiment. Its attack surface traditionally comprised publicly accessible web applications and portals hosted by governments, educational institutions, and commercial enterprises – where it orchestrated high‑volume DDoS using the MegaMedusa tool, defaced websites for propaganda purposes, and leaked stolen data through Telegram channels. In recent campaigns the group has broadened its threat horizon to include industrial control systems (ICS). Reports from Unit 42 show a dedicated sub‑team – branded Cyber Av3ngers or CL‑STA‑1128 – targeting Rockwell Automation and Allen‑Bradley PLCs. They employ AI‑driven spear‑phishing to harvest privileged credentials, subsequently performing lateral movement across corporate networks and executing remote factory resets via hijacked Intune sessions. Custom wiper payloads (Hatef for Windows, Hamsa for Linux) are delivered through multi‑stage loaders and the infostealer Rhadamanthys is also observed. The collective’s operations indicate a tactical shift from purely public‐facade disruption to more invasive infrastructure sabotage, underscoring an increased capacity to blend opportunistic attacks with targeted, politically motivated campaigns. Despite this evolution, RipperSec relies heavily on community participation and publicly available tools rather than specialized hardware or sophisticated custom malware. Overall, RipperSec’s activities illustrate a modern hacktivist threat model that combines low‑cost, high‑visibility tactics with escalating industrial sabotage capabilities to influence geopolitical narratives while destabilizing critical services.

Goals & Targeting

Targeted Sectors

Financial services
Government
Telecommunications
Healthcare
Defense
Education
Critical infrastructure
Energy
Manufacturing
Media
Transportation
Retail
Non profit
Aviation
Information technology
Hospitality
Legal services
Gaming
Utilities
Aerospace
Construction

Targeted Countries / Regions

IL
IR
AE
US
AU
IN
UA
GB
KR
TW
FR
SA
DE
RU
TR
CN
EG
JP
IQ
PL
BR
ES
NG
NL
VN
SG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 11 hours ago

Executive Summary

RipperSec is a pro‑Palestinian hacktivist collective that mounts public web DDoS campaigns, defacements and data leaks while targeting government, educational, industrial control and critical infrastructure sites perceived to support Israel or the United States. Their operations leverage readily available tools such as MegaMedusa for DDoS, AI‑enhanced phishing, and custom wiper malware (Hatef/Hamsa) to disrupt services and compromise remote management systems like Microsoft Intune. The group has expanded from web attacks into OT/ICS environments, exploiting PLC vulnerabilities and enabling remote factory resets.

Goals & Targeting

RipperSec’s strategic objective is primarily political disruption – to cast a negative light on Israel and its allies by exposing vulnerabilities in government and commercial systems. The group targets institutions that symbolically represent state authority, technological progress or economic stability: ministries, universities, energy suppliers, telecommunications providers, OT/ICS manufacturers, and global corporations with Israeli ties. Their targeting profile is broad yet purposeful; they choose high‑profile entities for maximum visibility while also striking industrial assets to demonstrate tangible harm. By leveraging community-based operations and open-source tools, they lower operational barriers, enabling rapid deployment of campaigns aligned with current geopolitical events.

Enhanced Description

Key Capabilities

  • Public web DDoS attacks
  • Use of MegaMedusa public attack tool
  • Targeting OT/ICS PLCs (Rockwell Automation, Allen‑Bradley)
  • AI‑enhanced spear‑phishing to obtain valid accounts
  • Lateral movement via hands‑on keyboard techniques and Intune hijacking for remote factory resets
  • Delivery of custom wiper malware (Hatef for Windows, Hamsa for Linux) via multi‑stage loaders
  • Deployment of infostealer Rhadamanthys
  • Website defacement
  • Data leak on Telegram/dark web channels

MITRE ATT&CK Tactics

Credential Access
Impact
Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1113
T1078
T1491.001
T1498
T1027
T1566.001
T1190

Software / Tooling

MegaMedusa
Hatef
Hamsa
Rhadamanthys
Dindoor
Fakeset
SeaDuke
Spear-pitching campaigns
Telegram
GitHub

Campaigns & Victims

Historically, RipperSec has executed synchronized, high‑profile DDoS bursts (e.g., attacks against Australian Moodle instances) timed with the Iran–Israel–US conflict to maximize propaganda impact. The group demonstrates a rapid operational tempo, announcing campaign windows via Telegram and other social channels and then deploying attack vectors almost immediately. Victim types span from public sector web portals to commercial e‑learning platforms and, more recently, industrial control stations. Notable past operations include the MegaMedusa‑driven DDoS against propeller‑drones.com, a defacement campaign on a UAE government site, and a sabotage push targeting Rockwell Automation PLCs marked by remote factory resets. The pattern suggests an evolving strategy that blends opportunistic public attacks with more targeted infrastructure strikes as part of a broader political agenda.

IOC Patterns

  • Domain names of targeted websites
  • Malware file names (e.g., Hatef.exe, Hamsa.bin)
  • Telegram channel identifiers used for data leaks
  • Defacement page URLs

Recommended Actions

  • Monitor threat actor chatter and scheduled attack announcements via intelligence platforms for early warning
  • Implement OT/ICS monitoring and anomaly detection on PLC networks
  • Patch known vulnerabilities in Rockwell Automation and Allen‑Bradley PLCs
  • Block or rate‑limit DDoS vectors against critical infrastructure assets
  • Enforce MFA and monitor credential usage on Intune and remote management tools
  • Deploy intrusion detection systems to detect multi‑stage loader signatures
  • Deploy web application firewalls and secure configuration baselines for public-facing services

Suggested Tags

hacktivist
pro-Palestinian
politically-motivated
RipperSec
OT-ICS
PLC
Spearphishing
Wiper Malware
Infostealer
Iran-backed
CommandandControl
Remote Factory Reset
DDoS
Defacement
Industrial Control System

Confidence Assessment

The confidence in the core attribution of RipperSec’s public DDoS and defacement activities is high, supported by multiple independent threat reports citing MegaMedusa usage and Telegram coordination. Confidence regarding their recent OT/ICS targeting remains moderate; it is largely based on third‑party analyses describing tactics and target selection but lacks direct evidence such as signed malicious code or confirmed infrastructure. Key information gaps include the group’s definitive leadership, precise operational timelines (first seen/last seen), full technical stack for remote factory reset exploits, and a comprehensive list of affected industrial control systems.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 Filename 1

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Cyber Av3ngers
  2. blog.talosintelligence.com — Cited by web research for: the Handala Hack Team
  3. cyberxtron.com — Cited by web research for: the 313 Team
  4. attack.mitre.org — Cited by web research for: T1078.001
  5. www.group-ib.com — Cited by web research for: Dark
  6. https://www.radware.com/blog/security/megamedusa-rippersec-public-web-ddos-attack-tool/ — Cited by AI analysis.
  7. https://www.orangecyberdefense.com/fileadmin/global/CyberIntelligenceBureau/Gangs_Investigations/rippersec/RipperSec_CI — Cited by AI analysis.

Intel Summary

12

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

Data Exfiltration
DDoS
Government Targeting
Hacktivism
Hactivism
Pro-Palestinian
Data Breach
Cyber-Physical Systems
Government Organizations
Educational Institutions
Malaysia
Middle East and North Africa (MENA)
Southeast Asia
hacktivist
pro-Palestinian
politically-motivated
RipperSec
OT-ICS
PLC
Spearphishing
Wiper Malware
Infostealer
Iran-backed
CommandandControl
Remote Factory Reset
Defacement
Industrial Control System

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
M
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.