Home
Glossary
Anonymous Sudan
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

Anonymous Sudan threat actor

Anonymous Sudan is a hacktivist group that emerged in January 2023 and became known for a high-tempo campaign of distributed denial-of-service (DDoS) attacks against organizations in the United States, Europe, the Middle East, and beyond. The group presented itself as Sudanese hacktivists retaliating against perceived anti-Muslim acts, but its target selection consistently aligned with pro-Russian, anti-Western interests, and it operated closely with the pro-Russian group Killnet. Microsoft tracks the group as Storm-1359. In October 2024, the US Department of Justice unsealed an indictment against two Sudanese brothers alleged to run the operation and announced the seizure of its DDoS tooling. Anonymous Sudan stood out less for technical novelty than for scale, showmanship, and the fact that it sold its attack capacity to others as a DDoS-for-hire service. This page covers the group's origins and disputed attribution, how it operated, its notable attacks, the 2024 law-enforcement takedown, and how organizations defend against attacks of this kind.

Key takeaways

  • DDoS at scale. Anonymous Sudan is a DDoS-focused hacktivist group active from early 2023, responsible for tens of thousands of attacks against government, healthcare, technology, and infrastructure targets worldwide.
  • Its attribution is contested. It claimed to be Sudanese hacktivists, many researchers suspected a Russian nexus given its Killnet alignment, and the 2024 US indictment identified two Sudanese brothers as the operators.
  • Rented infrastructure, not a botnet. Unlike many DDoS actors, it used paid cloud servers to launch powerful multi-vector attacks, and ran the tooling as a paid service for other criminals.
  • Microsoft tracks it as Storm-1359. Its DDoS tool was marketed under names including DCAT, Skynet, Godzilla, and InfraShutdown.
  • Disrupted in 2024. US authorities seized the attack tool in March 2024 and unsealed charges in October 2024, alleging more than 35,000 attacks and over $10 million in damage to US organizations.

Origins and disputed attribution

Anonymous Sudan first appeared on a Russian-speaking Telegram channel in January 2023, shortly after a public Quran burning by the far-right activist Rasmus Paludan in Sweden. Its stated mission was to attack any country or organization it viewed as engaging in anti-Muslim or anti-Sudanese activity, and its early campaigns, tagged #OpSweden and #OpDenmark, were framed as retaliation for that event.

The group's true identity was debated throughout its active period, and the evidence pointed in more than one direction. Several signals suggested a Russian nexus: it initially posted in Russian before shifting to Arabic, it joined Killnet's cluster of pro-Russian hacktivists, its targets frequently aligned with Kremlin interests rather than with Sudanese or Islamic causes, and it had the financial resources to rent attack infrastructure rather than relying on volunteers. At the same time, analysts were careful not to overstate the link. As CYE's threat intelligence team noted, there was no hard evidence tying the group directly to Russian state entities in the way that groups such as APT28 or APT29 are attributed.

The October 2024 US indictment added the clearest data point: it named two Sudanese brothers, Ahmed Salah Yousif Omer and Alaa Salah Yusuuf Omer, as the operators. Reporting on the case suggested the group's pro-Russian alignment was driven more by ideological affinity and by marketing its paid services alongside Killnet's notoriety than by direct state control. The name itself, the indictment noted, was a reference to the brothers' home country. Anonymous Sudan is also unrelated to the older Anonymous collective, which has publicly disclaimed any connection.

How Anonymous Sudan operates

Anonymous Sudan's methods were notable for a few consistent traits rather than for novel techniques.

  • Multi-vector DDoS. According to NETSCOUT's analysis, the group primarily combined TCP-based direct-path attacks with UDP reflection and amplification vectors such as DNS and SSDP, and favored HTTP floods against web server infrastructure. Observed attacks peaked at roughly 284 Gbps and 57 Mpps.
  • Rented infrastructure, not a botnet. Rather than a botnet of infected devices, the group used clusters of rented servers, which generate more traffic per node. The cost of that infrastructure was itself cited as a reason to doubt the grassroots-hacktivist claim.
  • Advance threats and propaganda. The group routinely announced targets on Telegram in advance, publicized outages using reachability tools such as Down Detector, taunted affected organizations, and timed attacks for peak-demand periods to maximize visible impact.
  • DDoS-for-hire. Anonymous Sudan built and sold its attack tool as a service, complete with rate cards and contact details, so a portion of attacks launched with its infrastructure were carried out by paying customers rather than the group itself.

The attack tool was marketed under several names: DCAT (Distributed Cloud Attack Tool), Skynet, Godzilla, and InfraShutdown. According to the US complaint, more than 100 users ran their own attacks using it.

Notable attacks

Over roughly eighteen months, Anonymous Sudan claimed or was linked to a long list of high-profile disruptions:

  • Microsoft (June 2023): intermittent disruption to Outlook and other Office services for close to a week. Microsoft attributed the activity to Storm-1359.
  • Cedars-Sinai Medical Center (Los Angeles): a DDoS attack disrupted web services and forced the emergency department to redirect incoming patients for roughly eight hours, a central element of the later criminal charges.
  • Government and public-sector targets, including the French government and multiple US federal agencies, alongside campaigns against Sweden, Denmark, Israel, Australia, and India.
  • Commercial and infrastructure targets, including SAS Airlines, Riot Games, payment providers, and telecommunications networks.

A recurring pattern was that the group attacked targets it had publicly threatened, treating visible downtime as proof of impact and as advertising for its paid service.

The 2024 law-enforcement takedown

In March 2024, US authorities obtained court-authorized warrants to seize the servers, command infrastructure, and source code behind Anonymous Sudan's DDoS tool, disabling it. In October 2024, a federal grand jury in the Central District of California unsealed an indictment against the two alleged operators.

Detail According to the US Department of Justice
Alleged operators Ahmed Salah Yousif Omer (22) and Alaa Salah Yusuuf Omer (27), Sudanese nationals.
Charges Conspiracy to damage protected computers; Ahmed Salah faces three additional counts of damaging protected computers.
Scale Tool linked to more than 35,000 DDoS attacks since early 2023.
Damage More than $10 million in damage to US organizations.
Tool seized DDoS tool known as DCAT, Skynet, Godzilla, and InfraShutdown.
Sentence exposure Ahmed Salah faces up to life; Alaa Salah faces up to five years.
Source: US Department of Justice indictment, October 2024. An indictment is an allegation; defendants are presumed innocent unless proven guilty.

The investigation drew on extensive private-sector cooperation, with Akamai, Amazon Web Services, Cloudflare, CrowdStrike, Flashpoint, Google, Microsoft, and PayPal among the firms that assisted US authorities. An indictment is an allegation; the defendants are presumed innocent unless proven guilty.

How to defend against attacks like Anonymous Sudan's

Because the group's core method was volumetric and application-layer DDoS, defense follows standard DDoS mitigation practice rather than anything actor-specific.

  1. Use always-on DDoS mitigation. A dedicated service with large bandwidth capacity and continuous traffic analysis can absorb attack traffic before it reaches the target, covering Layer 3, Layer 7, and DNS.
  2. Deploy a web application firewall (WAF). A WAF filters and blocks malicious HTTP traffic, which matters given the group's reliance on HTTP floods against web servers.
  3. Apply rate limiting. Capping the volume of requests a single source can make helps blunt application-layer floods without affecting legitimate users.
  4. Prepare for pre-announced campaigns. Because hacktivist groups often threaten targets in advance, monitoring threat intelligence channels and having an incident runbook ready lets teams raise defenses before a promised attack lands.

Expert insight: Track the behavior, not the brand

The Anonymous Sudan story is a useful reminder that hacktivist branding can be misleading. The group wrapped itself in a Sudanese, religiously motivated identity while behaving like a commercially minded, pro-Russian-aligned DDoS-for-hire operation, and its real operators turned out to be two individuals rather than a grassroots collective or a state unit. For defenders, chasing the label is less productive than tracking the observable behavior: the attack vectors, the infrastructure, and the advance-warning patterns.

This is where a CTI-led approach matters. Sekoia is a European cybersecurity vendor whose in-house Threat Detection & Research team tracks hacktivist and DDoS-oriented threat actors. That intelligence feeds the platform so that activity from groups like this can be recognized in context: an announced campaign on a monitored channel, a known attack fingerprint, or a spike in multi-vector traffic, rather than treated as isolated noise. Combined with standard DDoS mitigation at the network edge, contextual threat intelligence helps teams anticipate pre-announced campaigns and prioritize the targets a given actor is most likely to hit next.