The Syrian Electronic Army (SEA) is a pro-Assad, Syrian state-linked threat actor known for a blend of propaganda-driven intrusions, account compromise, website defacement, DNS and infrastructure hijacking, credential theft, and targeted malware operations. The group emerged during the Syrian civil war and became widely known for targeting Western media organizations, social media accounts, NGOs, corporate entities, and Syrian opposition figures in support of the Assad regime’s information and security objectives. SEA operations have included high-profile website defacements and content manipulation, including attacks on major media outlets and U.S. government-related websites, as well as DNS hijacking activity affecting prominent online services. The group is also associated with social-engineering-led compromises of social media and email accounts used to spread false information and pro-Assad messaging. Public reporting has tied SEA to the compromise of a major newswire social media account used to publish a false report that briefly disrupted financial markets. Beyond overt defacement and influence activity, SEA has been linked to targeted surveillance and malware delivery against activists and opposition members. Malware families associated with this activity include BlackShades RAT, XTreme RAT, Dark Comet RAT, and Android surveillance tooling such as SpyNote, SandroRat, AndoServer, and SLRat in broader Syrian state-linked campaigns. Reported capabilities in these operations include credential theft, remote access, screenshot capture, audio recording, location tracking, SMS and contact theft, call-log collection, camera access, and broader device surveillance. Social media honeypots and lure-based delivery have also been associated with the actor’s ecosystem. SEA has also been tied to data breaches and website manipulation against private-sector targets, including the compromise of a major media publisher that resulted in leaked user credentials and fraudulent content posted on the victim’s site. Reporting additionally links the group to lower-profile ongoing operations against Syrian opposition targets and to infrastructure overlaps with Syrian state telecommunications entities. The actor is widely assessed as aligned with Syrian government interests and is commonly regarded as a Syrian state-sponsored hacking group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
70 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a historical comparison to a prior defacement of Army websites.
Referenced as a historical example of a prior defacement of U.S. Army-related websites.
Mentioned as an example of a known actor that has used Arabic-language lure documents disguised as government forms in targeted campaigns.
Attributed with the 2014 attack on Forbes that leaked over 1 million user accounts and resulted in fake news stories being posted to forbes.com.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.