Education
Anonymous Sudan: The new hacktivists on the block
Hacktivist group Anonymous Sudan is famously known for their Distributed Denial of Service (DDoS) attacks on their victims. Let’s take a deeper look into who they are, their preferred method of attack and how to protect yourself from such an attack.
The hacktivist group Anonymous Sudan has been getting a lot of attention in recent years due to their attacks on high-profile organizations and websites such as Microsoft, UPS and, most notably, Archive of Our Own (ao3.com). Let’s take a deeper look into who they are, their preferred method of attack and how to protect yourself from such an attack.
Who are they?
Anonymous Sudan’s origins have been traced back to January 2023, where they started simply as a Telegram group and evolved from there. The group of hackers claim to be from Sudan, however few believe this to be true. They primarily target are any so-called anti-Muslim rhetoric, however many of their victims did no such thing. Theories abound about their true reason for being and their origins. However, their primary method of attack is most intriguing to those operating in the cyber world.
Before we get into that, let’s clarify something. This group is in no way affiliated with the hacktivist group known as Anonymous, who clearly distanced themselves from Anonymous Sudan soon after their conception in January 2023. Although theories suggest that the group got their name from the Sudan attack operated by Anonymous back in 2019, this has not been confirmed. This led many to believe they are a false flag, hiding their true origins and identity behind Anonymous and the Sudan project. This brings the true intentions of the group into question and leaves experts wondering if their hacktivism is genuine or simply for show. Experts have linked this group to Russia; although the group has strongly denied any association with Russia, Anonymous Sudan later admitted to being affiliated with KillNet, a Russian-backed hacktivist group funded by the Russian government, as well as aligning with many of the Russian government’s ideologies and propaganda.
Method of attack: DDoS
Anonymous Sudan is famously known for their Distributed Denial of Service (DDoS) attacks on their victims. The attacks simply involve overloading the server with fake requests, making the server unable to complete any requests and freezing the server until the requests are removed or completed. Although this sounds simple, it is a common method of attack for many hacktivist groups, including KillNet and REvil (a Russian-backed group that is no longer operational), which have been known to bring software, organizations, and websites down until they are resolved, which can take hours, days or even weeks. Explore our free course about DDoS attacks.
Research into the group has shown that although they have labelled themselves hacktivists, they do not perform the hacks themselves. The group has been known to prefer HTTP-based DDoS attacks which are more effective in their attack but require a lot of time, skill, and money to fund and perform. This type of attack specifically targets Layer 7, the top layer of a specific website that makes sure users can access and use the website through the layer below Level 7; thereby making the website useless to users since they can no longer access anything on the website. Other types of Layer 7 DDoS attacks include overloading the server that the website is hosted on; or slowing down the website server to the point the connection is kept open when a user clicks a link on the website and continuously runs until the request is fulfilled.
This method of attack shows that Anonymous Sudan has a lot of resources, enabling them to hire other well-known hacktivist groups such as KillNet or one of their affiliates to perform this preferred type of DDoS attack on their victims. This makes them stand out among other groups and has landed them notoriety for their attacks; after all, this method of attack is rarer and harder than a simple DDoS attack on a network or application.
How to protect yourself against a DDoS attack
Although Anonymous Sudan are relatively new to the hacktivist world, they have clearly made their presence known and are gaining in popularity on Telegram and elsewhere. They clearly like to focus on certain sectors such as financial institutions, government institutions, cloud service providers and websites.
The questions surrounding their origins and backers aside, this group have made a name for themselves, and it doesn’t look like they plan on stopping anytime soon. Some ways to ensure your business or organization does not fall victim to a DDoS attack is to ensure:
- Your firewalls and cybersecurity protocols are in place and working to their maximum capacity.
- That there is a clear incident response and recovery describing what to do in the event of an attack.
- That all online networks and servers are capable of handling a spike in requests and are protected to avoid website, system and/or network failure.
For bigger organizations, it would be best to hire a team of experts such as a Security Operations Center (SOC), who monitor the network and servers 24/7 and can respond quickly to any emerging threats.
Conclusion: Anonymous Sudan are the new threat on the horizon
To conclude, Anonymous Sudan are a group of hackers who claim to be hacktivists. However, experts believe they are a false flag and are instead hiding behind the hacktivist label to hide their true intentions. Their preferred method of attack is a DDoS attack, which overwhelms servers and renders them incapable of acting on user requests. There are a few ways to protect yourself and organization from a DDoS attack, such as ensuring effective cybersecurity protocols and efficient incident response and recovery.
Do you think your organization could handle a DDoS attack?