Special Features

Cybersecurity Month

Anonymous Sudan isn't any more: Two alleged operators named, charged

Gang said to have developed its evilware on GitHub – then DDoSed GitHub


Hacktivist gang Anonymous Sudan appears to have lost its anonymity after the US Attorney's Office on Wednesday unsealed an indictment identifying two of its alleged operators.

The indictment [PDF] named Sudanese nationals Ahmed Salah Yousif Omer and Alaa Salah Yusuuf Omer as members of Anonymous Sudan. An accompanying announcement accused the pair of "operating and controlling Anonymous Sudan, an online cyber criminal group responsible for tens of thousands of Distributed Denial of Service (DDoS) attacks against critical infrastructure, corporate networks, and government agencies in the United States and around the world."

Both were charged with one count of conspiracy to damage protected computers. Ahmed Salah was also charged with three counts of damaging protected computers.

Those charges stem from incidents in the US that saw attacks on the Department of Justice, the Department of Defense, the FBI, the State Department, Cedars-Sinai Medical Center in Los Angeles, Microsoft, and Riot Games.

Anonymous Sudan is also thought to have attacked OpenAI, the government of France, and Israeli organizations.

The group is believed to have ties to Russia.

The announcement revealed that it had already degraded the crew's capabilities by working with the FBI to seize and disable its Distributed Cloud Attack Tool (DCAT), which the group is alleged to have used for its own DDoS attacks. It's further claimed that Anonymous Sudan offered DCAT as a service to other criminal actors.

The indictment detailed how the accused chatted with clients and prospects on Telegram channels – sending messages such as "I am carrying out an organized attack on the United States. We can target the airport."

After that threat, messages were exchanged that reported on data gathered by internet resource availability monitoring service check-host.net, which was taken as proof that DDoS attacks succeeded.

The indictment also alleges that the crew built an API to its wares and developed code using GitHub – and also launched a DDoS against GitHub in January 2024.

Rebecca Day of the FBI Anchorage Field Office, the special agent in charge of the matter, said "With the FBI's mix of unique authorities, capabilities, and partnerships, there is no limit to our reach when it comes to combating all forms of cyber crime and defending global cyber security."

Per the Washington Post, the two accused were arrested in March but it is not known in which country they were cuffed, nor if extradition has been effected or is possible.

Maybe the FBI does have limits, after all. ®

Send us news
5 Comments

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

Release the Kraken!

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Merde! Macron's bodyguards reveal his location by sharing Strava data

It's not just the French president, Biden and Putin also reportedly trackable

Brazen crims selling stolen credit cards on Meta's Threads

The platform 'continues to take action' against illegal posts, we're told

AWS Cloud Development Kit flaw exposed accounts to full takeover

Remember Bucket Monopoly? Yeah, it gets worse