Also known as: Jabaroot DZ, tracked as
Jabaroot emerged as a prominent threat vector in the North African cyber landscape, focusing primarily on data leaks and political sabotage. The group has repeatedly targeted Moroccan state bodies—most notably the CNSS and the Ministry of Labor—successfully extracting sensitive personal data on an estimated two million citizens. Their operations have not only compromised confidential records but also involved defacement campaigns aimed at undermining confidence in public institutions. Analysis of available intelligence indicates that Jabaroot leverages a mix of web application exploitation, social engineering (likely spear‑phishing), and custom or borrowed RAT platforms to establish persistence within target networks. Once inside, they employ standard exfiltration channels to leak data to external domains such as demo‑cloud.space and other malicious domain hosts while periodically broadcasting the stolen content to attract media attention. The group’s activities are closely tied to regional geopolitical dynamics; heightened cyber hostilities between Morocco and Algeria in 2024–25 coincide with a surge in Jabaroot attacks. The intent appears dual: to compromise critical state data for intelligence gathering and to use the resulting leaks as propaganda tools that reinforce accusations of institutional vulnerability within Morocco. While public reports confirm their successful breaches, technical details about their tooling footprint remain sparse, leaving gaps regarding the exact malware families or infrastructure they consistently employ.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Jabaroot, an Algerian hacker group also known as Jabaroot DZ, has carried out large‑scale data exfiltration campaigns against Moroccan government institutions, stealing personal and financial information from the National Social Security Fund (CNSS) and other ministries. The attacks appear driven by socio‑political motives tied to Algeria–Morocco tensions and exhibit typical hacktivist APT behavior such as public disclosure of stolen material and website defacement.
Goals & Targeting
Jabaroot’s strategic objectives align with espionage and political hacktivism. By targeting government ministries, defense agencies, telecom operators, and key financial institutions across multiple countries—including Morocco, Algeria, the United States, Russia, India, and Ukraine—they aim to acquire personal, financial, and potentially classified data for both covert intelligence use and public dissemination. Their selection of victims appears governed by perceived political leverage: leaking citizen information or critical infrastructure vulnerabilities serves to erode trust in state systems while simultaneously projecting pressure on adversarial governments.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Jabaroot’s operational tempo has accelerated in the wake of heightened Algeria–Morocco tensions, with a series of coordinated attacks spanning 2024 and 2025. The group typically selects high‑profile governmental targets, extracts personal and financial data, then publicly releases the stolen material to amplify its political message. Notable incidents include the CNSS breach, the Ministry of Labor defacement, and multiple public leaks via malicious domains. Despite lacking large‑scale ransomware deployments, Jabaroot’s data‑leak campaigns mirror classic APT patterns—staged exfiltration, use of cloud‑based staging servers, and strategic disclosure timelines. The group maintains a blend of custom and borrowed malware, leveraging both legacy RATs and known spam‑delivery delivery frameworks (e.g., Emotet) to penetrate targets. Their attacks often culminate in the use of publicly monitored C2 domains, indicating an intention to remain observable enough for propaganda purposes. While evidence points to an organized operational model, the absence of public threat intelligence on infrastructure rotation or advanced cryptographic exfiltration suggests that Jabaroot operates at a moderate sophistication level compared to fully managed APTs.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core facts—Jabaroot’s origin as an Algerian group, its documented breaches of Moroccan government entities (CNSS and Ministry of Labor), and the political context underpinning these attacks—are corroborated by multiple credible reports (Check Point Research, Cyfirma). However, specific technical details such as precise malware variants, persistence mechanisms, and exact infrastructure are inferred from limited IOC samples and generic tool references. Consequently, confidence in the actor’s general objectives and impact is high, while confidence regarding granular capabilities, toolset, and full campaign chronology is moderate. Further investigation is warranted to confirm current operational posture, verify any escalation in ransomware or credential‑theft techniques, and assess the potential expansion into other target regions outside North Africa.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
41
Tools
0
Campaigns
39
IOCs
0
Observed Data
5
Tactics