AntiSec was a hacktivist campaign and loose collective associated with Anonymous and, in part, former LulzSec participants. Active primarily in 2011 and 2012, it focused on anti-law-enforcement, anti-security-industry, and anti-government operations, while also targeting military contractors, private intelligence firms, and organizations viewed as aligned with state surveillance or repression. AntiSec is closely associated with Jeremy Hammond and Hector Xavier Monsegur (Sabu), although the broader banner encompassed multiple participants and affiliated cells rather than a single centralized organization. The group is best known for the compromise of Stratfor, a U.S. private intelligence company, in which attackers stole a large archive of internal emails and customer data and exposed payment-card information that was later used fraudulently. Stolen Stratfor emails were subsequently provided to WikiLeaks for publication. AntiSec also claimed or conducted intrusions affecting U.S. law-enforcement organizations, the Arizona Department of Public Safety, the New York State Association of Chiefs of Police, the California Statewide Law Enforcement Association, IRC Federal, and Vanguard Defense Industries. Additional reported activity included attacks on Turkish government websites and operations framed as retaliation for police treatment of Occupy Wall Street protesters. Operationally, AntiSec used website and application exploitation, including SQL injection and web administration compromise, to gain initial access; credential theft and password cracking to expand access; abuse of weak upload controls to obtain code execution; and follow-on access into mail systems, forums, and internal collaboration platforms. Reported behavior included large-scale data theft, publication of stolen documents and personal information, website defacement, service disruption, and destructive actions against compromised servers. The group repeatedly exfiltrated emails, passwords, personal records, and other sensitive data from victims and publicly released selected material to embarrass targets, expose alleged misconduct, and support political messaging. AntiSec’s targeting and rhetoric place it firmly in the hacktivist tradition rather than financially motivated cybercrime, even though some operations involved theft and misuse of payment-card data. Its campaigns emphasized opposition to law enforcement, prisons, surveillance, military contracting, and parts of the cybersecurity industry, and it encouraged broader participation under an anti-security-state banner.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AntiSec is referenced in connection with Jeremy Hammond’s role in the 2012 hack of Stratfor and the subsequent publication of stolen company emails via WikiLeaks.
Anonymous-associated hacker group involved in the Stratfor breach and publication of stolen credit card numbers and client records.
Hacktivist/anarchist hacking crew associated with Jeremy Hammond that conducted intrusions, data theft, website defacements, and leaks against law enforcement, police suppliers, private intelligence firms, and government-related targets, including the Stratfor breach.
Hacktivist group involved in the 2011 Stratfor hack, theft of millions of internal emails, and associated financial crimes using stolen Stratfor customer credit cards.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.