Lizard Squad is a cybercriminal collective best known for high-profile distributed denial-of-service attacks against online gaming services, particularly during 2014–2016. Its targets included Sony PlayStation Network, Microsoft Xbox Live, Blizzard Battle.net, and other gaming platforms. The group disrupted PlayStation Network and Xbox Live simultaneously on Christmas Day 2014, establishing its notoriety through service outages and public taunting. Lizard Squad commercialized its attack infrastructure through Lizard Stresser, a DDoS-for-hire service launched in January 2015. The group is associated with BASHLITE, also known as Gafgyt, a Linux and embedded-device botnet malware family used for DDoS attacks. BASHLITE compromises vulnerable devices through techniques including Shellshock exploitation and brute-force authentication using common credentials, and supports multiple processor architectures and TCP- and UDP-based flooding. Beyond DDoS activity, Lizard Squad compromised Malaysia Airlines' domain configuration, redirecting visitors to a defacement page branded 'Official Cyber Caliphate.' The group also issued a false bomb threat against a flight carrying Sony Online Entertainment president John Smedley, causing its diversion, and threatened individual gaming livestreamers with DDoS attacks. Its provocative extremist branding does not establish affiliation with Islamic State. Known members included Julius Kivimäki, also known as Zeekill. Law-enforcement investigations identified members in the United States and the Netherlands and documented overlapping membership with PoodleCorp, a related but distinct hacking group. Multiple members faced arrests and prosecutions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Teenage hacker group discussed for its 2014 DDoS attack against Xbox and PlayStation and as part of the broader evolution of youth cybercrime gangs.
Operated the "Lizard Stresser" DDoS-for-hire service used to launch attacks against online targets.
Cybercrime group known for distributed denial-of-service (DDoS) attacks against high-profile online services (e.g., gaming networks).
DDoS-focused cybercrime group known for high-profile service disruption attacks (e.g., Xbox Live and PlayStation Network).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.