Also known as: keymous, Keymous Plus, tracked as
Keymous+ (also known as Keymous or Keymous Plus) has emerged as a prominent hacktivist actor in the Middle East region, executing over 700 distributed denial of service attacks against governmental, telecommunications, financial‑services, defense, and critical‑infrastructure targets. The group demonstrates a multi‑faceted operational model: it exploits publicly disclosed CVEs such as CVE‑2026‑1281 and CVE‑2024‑4577 for initial access and persistence, harvests and exfiltrates sensitive data—including more than 300,000 records from Israel's Ministry of Education—and then launches high‑volume DDoS blasts that saturate target networks. Keymous+ coordinates its campaigns through a network of Telegram channels, enabling rapid target selection and botnet mobilization. Besides traditional web‑based exploits, the actor leverages compromised Internet‑of‑Things devices and commercial "DDoS‑for‑hire" platforms to aggregate attack bandwidth. Their operations are timed with regional political events, suggesting an agenda aligned with geopolitical tensions in the region. The threat actor’s tactics span initial access via vulnerability exploitation, persistence through configuration changes on hosts, data exfiltration using standard protocols, and eventual impact deliveries that include both service disruption (DDoS) and data destruction. Their public statements emphasize the desire to highlight political grievances or achieve strategic objectives rather than purely financial gain. Keymous+ continues to evolve its capabilities; recent reports indicate use of advanced persistence techniques such as registry modifications, scheduled tasks, and exploitation of authentication bypass flaws. Analysts advise maintaining rigorous vulnerability management and enhanced DDoS protection layers as part of the defense posture against this actor.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Keymous+ is a politically motivated threat actor that orchestrates large‑scale DDoS campaigns against critical infrastructure, government ministries, and various sectors across Arab countries and beyond. The group exploits high‑impact vulnerabilities for initial access, leverages compromised IoT devices and botnets to amplify attacks, and coordinates operations through hundreds of Telegram channels. Their activities are characterized by rapid deployment, persistent threat actions, and substantial disruption objectives.
Goals & Targeting
The group’s strategic objectives revolve around politically driven disruption. By targeting ministries, telecommunications networks, financial institutions, media outlets, and other mission‑critical sectors across dozens of countries—including France, Pakistan, India, Saudi Arabia, UAE, Ukraine, Iran, Egypt, the United States, Israel, and Germany—Keymous+ seeks to embarrass state actors, cause operational paralysis, and amplify geopolitical messages. Their target selection appears tied to institutions that hold symbolic or strategic value within regional conflicts, with an emphasis on high‑visibility disruptions.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Keymous+ showcases a high‑tempo, nation‑wide campaign style. In a single operation, the actor launched over 149 hacktivist DDoS bursts covering 16 countries within days, and its broader activity portfolio is reported at more than 700 attacks worldwide. Victims predominantly include government ministries and critical infrastructure, with a notable record of exfiltration from Israel’s Ministry of Education. The operations combine initial exploitation using known CVEs, persistence via configuration changes or scheduled tasks, followed by mass‑traffic disruptions employing botnets sourced locally and through third‑party service providers. Their use of thousands of Telegram channels allows rapid dissemination of attack plans and target lists.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in Keymous+’s core capabilities and campaign behavior is moderate to high, based on multiple independent reports documenting large‑scale DDoS operations, CVE exploit usage, and sectoral targeting. However, gaps remain regarding precise timelines for each attack vector, the full extent of their back‑end infrastructure (e.g., exact numbers of compromised IoT devices), and detailed attribution evidence linking all incidents conclusively to the same actor. Continued monitoring of threat forums, Telegram channels, and vulnerability disclosures is necessary to refine understanding.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
47
Tools
0
Campaigns
7
IOCs
0
Observed Data
2
Tactics