Lizard Squad was a high-visibility hacker collective active primarily in the mid-2010s and best known for disruptive distributed denial-of-service operations against online gaming platforms and related services. The group gained broad notoriety for attacks that disrupted PlayStation Network and Xbox Live on Christmas Day 2014, and it was also linked to attacks against other gaming services including Blizzard infrastructure and titles such as Pokémon GO, World of Warcraft, and League of Legends. Beyond service disruption, the group commercialized its activity through the Lizard Stresser attack-for-hire service, an early prominent example of the booter or stresser model. The group has been associated with the BASHLITE malware family, also known as Gafgyt and LizardStresser, a Linux and IoT-focused botnet used to launch DDoS attacks. Reported tradecraft tied to this ecosystem included exploitation of Shellshock, brute-force login attempts against exposed devices, scanning for vulnerable systems, and use of compromised Linux and embedded devices to generate attack traffic. Lizard Squad also used public social-media channels for taunting, claiming responsibility, and amplifying the psychological impact of operations. Lizard Squad’s activity was not limited to volumetric disruption. The group was tied to website compromise and defacement, including the Malaysia Airlines incident, and to harassment behavior surrounding gaming-related attacks. It also participated in cybercrime communities and forums, including Darkode. Multiple members or alleged members were later arrested in different jurisdictions, including individuals in the United States, the Netherlands, and Finland. Julius Kivimäki, also known as Zeekill and Ransom_man, was identified as a key member during the 2014 attacks. Lizard Squad is widely characterized as a precursor to later English-speaking cybercrime groups that blended public notoriety, online taunting, and commoditized attack services. Its dominant motivation was financial, reflected in its operation of DDoS-for-hire services and related criminal monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Teenage hacker group discussed for its 2014 DDoS attack against Xbox and PlayStation and as part of the broader evolution of youth cybercrime gangs.
Operated the "Lizard Stresser" DDoS-for-hire service used to launch attacks against online targets.
Cybercrime group known for distributed denial-of-service (DDoS) attacks against high-profile online services (e.g., gaming networks).
DDoS-focused cybercrime group known for high-profile service disruption attacks (e.g., Xbox Live and PlayStation Network).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.