Anonymous is a decentralized hacktivist collective that emerged from imageboard culture and evolved into a loose, leaderless movement conducting politically motivated cyber operations, online disruption, data leaks, and public influence campaigns. It is best known for operations framed around anti-censorship, anti-corruption, anti-authoritarian, and protest causes, with activity often organized under ad hoc campaign names and carried out by shifting participants rather than a stable membership structure. Common aliases include Anonymous Collective, Anonymous Hackers, and related variants. Anonymous has targeted governments, political parties, law enforcement organizations, corporations, financial services firms, media entities, extremist groups, and state-aligned institutions. Historically documented campaigns include retaliation against payment processors over WikiLeaks, operations against Scientology, support for the Tunisian revolution and Occupy movement, actions against the Ku Klux Klan, and later campaigns tied to the Russia-Ukraine war and anti-regime activity in Iran. During the Russia-Ukraine conflict, Anonymous publicly supported Ukraine and was associated with disruptive operations against Russian and Belarusian entities, including website takedowns, data breaches, and information operations. Anonymous also publicly claimed involvement in anti-regime broadcasting disruption under the #OpIran banner, although attribution for some such incidents remains unconfirmed. The collective’s tactics have included distributed denial-of-service attacks, website defacement, unauthorized access, data theft and publication, doxing, and public messaging intended to generate attention and reputational pressure. Anonymous-linked operations have also involved exfiltration of large datasets, including law-enforcement-related material in the BlueLeaks disclosure, and politically motivated defacements such as attacks on the Republican Party of Texas. The movement has repeatedly blended technical intrusion with propaganda value, using symbolic targets and media amplification to maximize political impact. Anonymous is not a nation-state actor. It is an amorphous transnational movement with no single command structure, and operations attributed to it vary widely in sophistication, discipline, and impact. Subgroups and adjacent formations have included offshoots such as LulzSec, while prominent individuals publicly linked to Anonymous over time have included figures such as Hector Monsegur (Sabu), Jeremy Hammond, and Aubrey Cottle. Because the Anonymous label is open and widely adopted, attribution to the collective often reflects claimed affiliation or branding rather than verified centralized coordination.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison point to Phineas Fisher in discussing hacktivism notoriety.
Mentioned as an example in a discussion of hacktivism and digital resistance movements.
Hacktivist collective discussed in the context of a documentary about motivation-driven cyber activity focused on visibility, disruption, embarrassment, pressure, and messaging rather than financial gain.
Mentioned as a rival hacktivist collective attacking ETA and doxing one of its members, prompting ETA's planned retaliation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.