Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Jabaroot

Also known as: Jabaroot DZ, tracked as

Description

Jabaroot emerged as a prominent threat vector in the North African cyber landscape, focusing primarily on data leaks and political sabotage. The group has repeatedly targeted Moroccan state bodies—most notably the CNSS and the Ministry of Labor—successfully extracting sensitive personal data on an estimated two million citizens. Their operations have not only compromised confidential records but also involved defacement campaigns aimed at undermining confidence in public institutions. Analysis of available intelligence indicates that Jabaroot leverages a mix of web application exploitation, social engineering (likely spear‑phishing), and custom or borrowed RAT platforms to establish persistence within target networks. Once inside, they employ standard exfiltration channels to leak data to external domains such as demo‑cloud.space and other malicious domain hosts while periodically broadcasting the stolen content to attract media attention. The group’s activities are closely tied to regional geopolitical dynamics; heightened cyber hostilities between Morocco and Algeria in 2024–25 coincide with a surge in Jabaroot attacks. The intent appears dual: to compromise critical state data for intelligence gathering and to use the resulting leaks as propaganda tools that reinforce accusations of institutional vulnerability within Morocco. While public reports confirm their successful breaches, technical details about their tooling footprint remain sparse, leaving gaps regarding the exact malware families or infrastructure they consistently employ.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Media
Financial services
Non profit
Education
Construction
Healthcare
Manufacturing
Hospitality
Energy
Critical infrastructure
Transportation

Targeted Countries / Regions

US
RU
PK
IN
UA
GB
AU
DE
FR
AE
KP
VN
IR
IL

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Jabaroot, an Algerian hacker group also known as Jabaroot DZ, has carried out large‑scale data exfiltration campaigns against Moroccan government institutions, stealing personal and financial information from the National Social Security Fund (CNSS) and other ministries. The attacks appear driven by socio‑political motives tied to Algeria–Morocco tensions and exhibit typical hacktivist APT behavior such as public disclosure of stolen material and website defacement.

Goals & Targeting

Jabaroot’s strategic objectives align with espionage and political hacktivism. By targeting government ministries, defense agencies, telecom operators, and key financial institutions across multiple countries—including Morocco, Algeria, the United States, Russia, India, and Ukraine—they aim to acquire personal, financial, and potentially classified data for both covert intelligence use and public dissemination. Their selection of victims appears governed by perceived political leverage: leaking citizen information or critical infrastructure vulnerabilities serves to erode trust in state systems while simultaneously projecting pressure on adversarial governments.

Enhanced Description

Key Capabilities

  • Large‑scale data exfiltration from government databases
  • Web application exploitation resulting in defacement
  • Use of command and control channels over legitimate cloud domains
  • Employment of RATs such as Gh0st and ROKRAT for persistence
  • Social engineering via spear‑phishing or malicious email attachments (inferred)
  • Credential theft and lateral movement within compromised networks

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access
Exfiltration
Command and Control

ATT&CK Techniques

T1190
T1071.001
T1041
T1048
T1083
T1055.002
T1036.003

Software / Tooling

Gh0st RAT
ROKRAT
Havex RAT
Emotet
Medusa Ransomware

Campaigns & Victims

Jabaroot’s operational tempo has accelerated in the wake of heightened Algeria–Morocco tensions, with a series of coordinated attacks spanning 2024 and 2025. The group typically selects high‑profile governmental targets, extracts personal and financial data, then publicly releases the stolen material to amplify its political message. Notable incidents include the CNSS breach, the Ministry of Labor defacement, and multiple public leaks via malicious domains. Despite lacking large‑scale ransomware deployments, Jabaroot’s data‑leak campaigns mirror classic APT patterns—staged exfiltration, use of cloud‑based staging servers, and strategic disclosure timelines. The group maintains a blend of custom and borrowed malware, leveraging both legacy RATs and known spam‑delivery delivery frameworks (e.g., Emotet) to penetrate targets. Their attacks often culminate in the use of publicly monitored C2 domains, indicating an intention to remain observable enough for propaganda purposes. While evidence points to an organized operational model, the absence of public threat intelligence on infrastructure rotation or advanced cryptographic exfiltration suggests that Jabaroot operates at a moderate sophistication level compared to fully managed APTs.

IOC Patterns

  • Domain-based C2 infrastructure (e.g., demo‑cloud.space, moroccoworldnews.com)
  • Malicious domains hosting ransomware binaries and exfiltration tools
  • Use of short or obfuscated domain names for staging servers

Recommended Actions

  • Implement multifactor authentication across all privileged accounts and critical systems.
  • Enforce strict email security controls—filtering attachments and tracking malicious URLs.
  • Apply timely patches to web applications and remediate known CVEs. Deploy network segmentation and monitor for anomalous outbound connections, especially DNS or HTTP traffic to questionable domains. Maintain an up‑to‑date incident response plan that includes data breach notification procedures. Conduct regular security awareness training focused on spear‑phishing, social engineering, and the recognition of defacement indicators.

Suggested Tags

APT
Espionage
Data Theft
Hacktivism
Government Targeting
North Africa
Cyber Conflict

Confidence Assessment

The core facts—Jabaroot’s origin as an Algerian group, its documented breaches of Moroccan government entities (CNSS and Ministry of Labor), and the political context underpinning these attacks—are corroborated by multiple credible reports (Check Point Research, Cyfirma). However, specific technical details such as precise malware variants, persistence mechanisms, and exact infrastructure are inferred from limited IOC samples and generic tool references. Consequently, confidence in the actor’s general objectives and impact is high, while confidence regarding granular capabilities, toolset, and full campaign chronology is moderate. Further investigation is warranted to confirm current operational posture, verify any escalation in ransomware or credential‑theft techniques, and assess the potential expansion into other target regions outside North Africa.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. research.checkpoint.com — Cited by web research for: phishing
  2. www.recordedfuture.com — Cited by web research for: Dark
  3. freemindtronic.com — Cited by web research for: Leverage
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: SAGE
  5. cybelangel.com — Cited by web research for: CVE-2026-63077
  6. https://research.checkpoint.com/2025/jabaroot-threat-intelligence — Cited by AI analysis.
  7. https://cyfirma.com/blog/morocco-cyberattacks-2024 — Cited by AI analysis.

Intel Summary

7

Techniques

41

Tools

0

Campaigns

39

IOCs

0

Observed Data

5

Tactics

Tags

APT
Critical Infrastructure
Data Exfiltration
Government Targeting
espionage
government-sector
North Africa
political-motivated
data-exfiltration
Espionage
Data Theft
Hacktivism
Cyber Conflict

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
D
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.