Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Aslan Neferler Tim

Aslan Neferler Tim

TLP:CLEAR
Active

Also known as: Lion Soldiers Team, Phantom Turk, the Lion Soldiers Team, General Osman, Kentucky

Description

Aslan Neferler Tim—also known as Lion Soldiers Team, Phantom Turk, General Osman or Kentucky—is a covert Turkish nationalist cell that surfaced publicly around late 2015 through its domain registration and Twitter activity. The group views itself as an Islamist guardian of the homeland, explicitly rejecting party affiliation while positioning its campaigns as defensive actions for Islam, nation, and flag. The organization’s operational modus operandi centers on large‑scale denial‑of‑service attacks that overwhelm target web services via request flooding, followed by brief but high‑impact outages. Complementing this, they routinely deface servers using image insertion or textual replacements to broadcast politically charged imagery or slogans. When sites are compromised, the group occasionally exfiltrates sensitive data, although most documented incidents focus on reputational damage rather than information theft. Affecting both Turkish and foreign infrastructure, Aslan Neferler Tim has struck high‑profile targets—including the Austrian Parliament’s website (causing a 20‑minute outage), Turkey’s Ministry of Foreign Affairs and Defence ministries, and municipal sites in Armenia, Iraq, Israel and the United States. The geographical spread demonstrates their ability to deploy attacks globally from modest infrastructure while maintaining strict ideological focus on entities perceived as hostile toward Turkish interests.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Media
Education

Targeted Countries / Regions

TR
IN
IL
US
DE
NL
IQ
IR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 days ago

Executive Summary

Aslan Neferler Tim (Lion Soldiers Team) is a Turkey‑based nationalist hacktivist group that has operated for roughly one year. Their attacks consist mainly of distributed denial‑of‑service (DDoS) floods and overt website defacements against governments, media outlets, financial institutions and education sites deemed critical of Turkish policy. The group portrays itself as a defender of Islam and the nation, targeting victims across Europe, the United States, the Middle East and South Asia.

Goals & Targeting

The group’s strategic objective is explicitly political: to retaliate against foreign actors—and increasingly domestic institutions—that criticize Turkish government policy or leadership. By incapacitating high‑visibility sites through DDoS and defacement, they aim to sow disruption, erode public confidence in opposition voices, and broadcast nationalist rhetoric. Their targeting profile skews toward governments, defense ministries, media outlets, educational institutions, and financial services that have issued statements critical of Turkey’s domestic or foreign actions.

Enhanced Description

Key Capabilities

  • Distributed Denial of Service (DDoS) via request flooding
  • Website defacement by image injection or text replacement
  • Compromise of individual sites leading to potential data leaks
  • Service request flood causing website downtime
  • Rapid recovery exploitation and exploitation of content management systems

MITRE ATT&CK Tactics

Impact

ATT&CK Techniques

T1498
T1499

Campaigns & Victims

The actor follows a consistent campaign pattern: rapid DDoS bursts followed by defacements to maximize political messaging. Operational tempo appears semi‑regular, with attacks timed to coincide with international diplomatic statements or domestic policy announcements. Victims are primarily governmental and public service sites; however, the reach extends to foreign financial and media entities across Europe, North America and the Middle East. Historical operations include the Austrian Parliament outage in early 2022, multiple Turkish ministry floods that same year, and city‑level defacements in partner nations—each featuring explicit nationalist iconography.

IOC Patterns

  • Domain-based request flooding targeting government websites
  • Image insertion on municipal sites to replace legitimate content
  • Replacement of page text with propaganda slogans
  • Exfiltration or leakage of data following site compromise

Recommended Actions

  • Deploy rate limiting and traffic filtering at network perimeter to mitigate sudden spikes typical of DDoS attacks
  • Employ dedicated anti‑DDoS scrubbing services for critical web assets
  • Implement WAF rules to block unauthorized content modifications on CMS platforms
  • Regularly audit and patch server software to close known exploitation vectors
  • Maintain up‑to‑date backups along with tested restoration procedures for affected websites

Suggested Tags

Political Motivated Attacks
Nationalist Hacktivist
Government Targeting
Defacement
DDoS
Islamic Ideology
Turkey Affiliated
Cross‑Border Operations

Confidence Assessment

Confidence in the attribution of attacks to Aslan Neferler Tim is moderate, relying on publicly available indicators such as consistent online persona and alignment of targeting themes. Key gaps remain due to absence of confirmed malware samples, undisclosed infrastructural details, and incomplete coverage of all campaign phases. Further intelligence would benefit from network traffic attribution and source code analysis of the group’s operational tools.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.vice.com — Cited by web research for: Defense
  2. apnews.com — Cited by web research for: India
  3. www.jpost.com — Cited by web research for: Iran
  4. www.newsweek.com — Cited by web research for: U.S.News

Intel Summary

2

Techniques

13

Tools

0

Campaigns

3

IOCs

0

Observed Data

1

Tactics

Tags

DDoS
Government Targeting
Hacktivism
Political Motivation
Defacements
Nationalism
Political Motivated Attacks
Nationalist Hacktivist
Defacement
Islamic Ideology
Turkey Affiliated
Cross‑Border Operations

Details

Type
Unknown
Primary Motivation
Ideology
Country of Origin
T
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.