Anonymous, also known as Anonymous Collective, is a decentralized hacktivist collective whose participants conduct cyberattacks and public campaigns for political and ideological purposes. It lacks a centralized command structure, and individuals or loosely organized groups can independently undertake operations under its name. Identifiable branches include Anonymous Italy. Its characteristic activities include distributed denial-of-service attacks, website defacement, targeted data breaches, publication of stolen information, and doxxing. These activities combine operational disruption with publicity and political messaging. Anonymous gained global prominence before 2017 and experienced renewed activity following Russia’s full-scale invasion of Ukraine in February 2022. Participants publicly supported Ukraine and declared a cyberwar against Russia. Operations claimed under the Anonymous name included disruption and defacement of Russian government, news, and corporate websites, DDoS attacks against Russian government services and the state broadcaster Russia Today, and publication of data allegedly stolen from federal agencies. Anti-war messaging accompanied these campaigns. Anonymous Italy also attacked Killnet infrastructure, and the broader collective announced support for that confrontation. Attribution requires particular caution because Anonymous is an open, decentralized identity rather than a single bounded organization. Criminal actors have invoked its name in DDoS extortion threats, but such claims do not establish affiliation with the collective.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of hacktivists who obtain confidential information through cyberattacks and leak it to expose wrongdoing, rather than relying on insider access.
Mentionné comme exemple historique de hacktivisme dans une discussion prospective sur la façon dont l’IA peut accroître les capacités d’acteurs peu qualifiés.
Referenced as an example of historical hacktivism in a discussion of how AI could enable a resurgence of lower-skilled, socially motivated attackers.
Referenced only as a comparison point to Phineas Fisher in discussing hacktivism notoriety.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.