The Jester, also known as th3j35t3r and Jester, is a self-described patriotic hacktivist and lone-actor persona widely associated with disruptive operations framed as pro-West or pro-U.S. causes. He has been described as an ex-U.S. military or military-contractor figure, though public reporting has often treated that biographical detail as purported rather than independently verified. The actor is best known for denial-of-service activity, propaganda-oriented web manipulation, and public messaging through social platforms. The Jester has repeatedly been linked to attacks against jihadist websites, WikiLeaks, and the Westboro Baptist Church. In the WikiLeaks case, he publicly claimed responsibility for early disruptions around the release of U.S. diplomatic cables and portrayed the action as an effort to prevent access to American secrets. Reporting also associates him with denial-of-service attacks against the Westboro Baptist Church in retaliation for anti-gay protests at U.S. servicemen’s funerals. He has also been cited as a rival and critic of Anonymous and LulzSec, publicly mocking those communities and threatening to expose members. Beyond service disruption, The Jester has used deception techniques to create the appearance of successful compromises. Notable activity attributed to him includes abuse of URL shorteners and cross-site scripting to produce convincing but non-destructive defacement illusions, including an incident involving the Russian Foreign Ministry’s website. These operations were designed to manipulate perception and media coverage rather than cause destructive impact. He has also been associated with the application-layer denial-of-service tool XerXeS, which has been described as more sophisticated than commodity volunteer DDoS tools used by some hacktivist communities. The actor’s operational profile is most consistent with hacktivist disruption, spoofing, and influence through spectacle rather than financially motivated intrusion. Although one malware-analysis reference noted a possible link between code associated with Jester Stealer and another criminal malware project, that observation does not establish that The Jester hacktivist persona operated those malware campaigns and is insufficient to characterize him as a malware operator at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a possibly linked threat actor/project because Jester Stealer may be rebranded from the same GitHub source used by Eternity Project.
Hacktivist-style propaganda and disruption activity using web manipulation tricks and DDoS attacks, including creating the false appearance of website compromise via XSS and shortened URLs.
Activist or patriot-hacker adversary of LulzSec, known for attacks on jihadist sites and WikiLeaks-related targets, and for attempting to track or disrupt LulzSec.
Self-described lone-wolf hacktivist focused on disrupting jihadist/terrorist-related sites; antagonistic toward Anonymous/LulzSec and threatens to expose members via doxing; conducted large-scale DDoS (e.g., against WikiLeaks).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.