Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Anonymous Sudan was not part of the original Anonymous movement. It was a separate operation that adopted the Anonymous name, claimed attacks through Telegram, and became known primarily for distributed denial-of-service (DDoS) campaigns. But the second half of the familiar description—“not Sudanese”—is no longer accurate as a definitive conclusion.

Early reporting found Russian-language communications, strong ties to the Russia-aligned group KillNet, and targeting that often served Russian geopolitical narratives. In October 2024, however, the U.S. Department of Justice indicted two Sudanese nationals and alleged that they operated and controlled Anonymous Sudan. The evidence now supports a more complicated description: an allegedly Sudanese-operated DDoS operation that worked closely with Russia-aligned cyber actors and presented itself as hacktivist while allegedly selling attack capacity to customers.

The short answer

  • Was it Anonymous? No evidence shows that Anonymous Sudan belonged to, was authorized by, or was governed by the decentralized Anonymous movement.
  • Was it Sudanese? The DOJ alleges that it was operated by Sudanese nationals, including individuals based in Sudan. That does not mean it independently represented Sudanese politics.
  • Was it Russian-backed? It was closely associated with KillNet and frequently aligned with Russian geopolitical interests. Direct control by the Russian government has not been established by the cited evidence.
  • What did it do? It launched DDoS attacks and allegedly operated a DDoS-for-hire service.
  • What happened? U.S. authorities seized key infrastructure in March 2024 and indicted two alleged operators on October 16, 2024.

How Anonymous Sudan emerged

Mandiant says the self-proclaimed group first appeared in January 2023, with a Telegram channel listed as beginning on January 18. Its public messaging invoked Sudan, Islam, and political grievances, while its main operational activity involved claims of DDoS attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft tracked the activity as Storm-1359. In its analysis of attacks affecting Microsoft services, Microsoft described Storm-1359 as primarily using layer-7 DDoS techniques, including HTTP(S) floods and cache-bypass attempts. The attackers used combinations of virtual private servers, rented cloud infrastructure, open proxies, botnets, and DDoS tools.

Telegram served several purposes at once: it was a place to announce targets, claim responsibility, publish propaganda, coordinate supporters, and promote the operation’s capabilities. A Telegram claim, however, is not by itself proof that the named group caused an outage.

Why the name “Anonymous” was misleading

Anonymous is best understood as a decentralized hacktivist brand and movement rather than a conventional organization with a membership register or central leadership. Different actors have used the name over the years.

Anonymous Sudan was a separate identity using that well-known brand. There is no cited evidence that it was an affiliate of the original Anonymous collective. The borrowed name likely helped the operation gain attention and credibility, while also signaling a confrontational hacktivist identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That distinction matters. Calling an operation “Anonymous” does not establish its organizational origin, ideology, or technical relationship to other people using the same label.

Why researchers initially doubted the Sudanese identity

Early reporting raised reasonable questions about whether the group was genuinely Sudanese:

  • It first appeared through a Russian-speaking Telegram channel.
  • Its early communications reportedly used Russian and English more prominently than Arabic.
  • Its targets and public rhetoric often matched Russian geopolitical interests.
  • It publicly aligned itself with KillNet, a Russia-aligned cyber collective.

Those observations supported descriptions such as “possibly Russian-linked” or “not demonstrably Sudanese.” They did not prove that no Sudanese people were involved. Online language, infrastructure, and political messaging can indicate influence or affiliation, but they do not reliably establish every operator’s nationality.

What the later U.S. case established—and what it did not

In October 2024, the U.S. Department of Justice announced an indictment against Ahmed Salah Yousif Omer and Alaa Salah Yusuuf Omer. Prosecutors alleged that the two Sudanese nationals operated and controlled Anonymous Sudan.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A related FBI affidavit said the investigation identified Sudan-based individuals leading the operation and that “Sudan” appeared to refer to the country where Ahmed had previously lived. The case documents describe alleged technical administration, programming, customer negotiations, and operation of the attack platform—not merely anonymous online supporters.

These are allegations. The defendants are presumed innocent unless proven guilty in court. The indictment makes the phrase “not Sudanese” too categorical, but it does not settle every question about the group’s political independence or foreign relationships.

Was Anonymous Sudan Russian-backed?

The strongest evidence concerns association and alignment, not proven state control.

Mandiant described Anonymous Sudan as a prominent KillNet affiliate in 2023 and said the group publicly declared allegiance to KillNet. In the period Mandiant studied, Anonymous Sudan accounted for approximately 63% of identified DDoS attacks claimed by the KillNet collective. Mandiant also observed targeting that often reflected Russian geopolitical interests.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That evidence can support descriptions such as:

  • Russia-aligned;
  • closely associated with KillNet;
  • apparently useful to Russian geopolitical narratives; or
  • possibly subject to outside investment or influence.

It does not, on the cited evidence, prove that the Kremlin created the group, that Russian intelligence directed its attacks, or that KillNet controlled every operation. Mandiant said it could not confirm cooperation with Russian security services.

Several relationships are possible without being equivalent: ideological alignment, cooperation with an affiliate, financial support, tasking by a state, and direct operational control. The available evidence supports the first two more strongly than the last two.

What did Anonymous Sudan actually do?

DDoS attacks attempt to overwhelm a website, application, or network service with enough traffic or requests to make it slow or unavailable. The technique can cause serious operational harm without stealing files or breaking into customer accounts.

Microsoft said Storm-1359 caused temporary availability impacts in early June 2023, affecting services including Outlook and OneDrive. Microsoft reported that it saw no evidence that customer data was accessed or compromised. In other words, the incident was a service-disruption attack, not a demonstrated Microsoft data breach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Taking down” a website can mean temporary unavailability, degraded performance, or disruption at an upstream provider. It does not necessarily mean permanent destruction, server compromise, or data theft. Public claims of responsibility should therefore be separated from independently observed technical attribution.

Targets and reported impact

Anonymous Sudan was associated in public reporting with attacks or claims involving Scandinavian Airlines, UPS, government agencies, technology companies, media organizations, Israeli targets, hospitals, and critical infrastructure. Not every public claim has the same level of independent confirmation.

The DOJ’s case provides stronger support for a broad set of alleged attacks and names victims including the Department of Justice, Department of Defense, FBI, State Department, Cedars-Sinai Medical Center, Microsoft, and Riot Games.

Target or category What can responsibly be said
Microsoft services Microsoft attributed temporary availability impacts to Storm-1359 and reported no evidence of customer-data compromise.
Cedars-Sinai Medical Center The DOJ alleged that an attack affected the emergency department and caused incoming patients to be redirected for approximately eight hours.
U.S. government and infrastructure victims The DOJ indictment names multiple alleged victims, including federal agencies and critical services.
Other publicly discussed targets These should be described as reported or claimed associations unless independently confirmed.

The Cedars-Sinai allegation illustrates why DDoS should not be dismissed as harmless online vandalism. Even without data theft, an outage can disrupt public services, redirect patients, create recovery costs, and become a highly visible piece of political theater.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Hacktivism or cybercrime?

The most accurate answer is both, but in different senses.

Anonymous Sudan used political, religious, and geopolitical explanations for its targets. Its public persona resembled hacktivism: attacks were announced, justified, and publicized as acts of protest or retaliation.

But the DOJ also alleged that the operators advertised and sold access to their DDoS infrastructure. The attack tool allegedly supported subscriptions, pricing, and negotiated customer access. That commercial model weakens the claim that the operation was purely a volunteer political movement.

A careful legal and operational description is therefore: an alleged cybercriminal DDoS-for-hire operation that also presented itself as hacktivist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The DOJ alleged that the tool was used in more than 35,000 DDoS attacks over approximately one year, including at least 70 attacks targeting computers in the greater Los Angeles area. It estimated more than $10 million in damages to U.S. victims. Those figures are government allegations and estimates, not final judicial findings.

The tools and the operation are not the same thing

Several names appear in reporting and court documents, but they should not be treated as interchangeable:

  • Anonymous Sudan: the public group identity and persona.
  • Storm-1359: Microsoft’s threat-tracking designation.
  • DCAT, Godzilla, Skynet, and InfraShutdown: names associated with the DDoS platform, tools, or infrastructure.

A threat-intelligence label may describe observed activity, while a court document may refer to a tool or service used by alleged operators. Separating these terms prevents the common mistake of treating a group name, a vendor label, and a piece of attack infrastructure as identical.

What happened after the U.S. investigation?

In March 2024, the FBI and U.S. prosecutors seized and disabled key servers, accounts, and source code associated with the DDoS tool. The action formed part of Operation PowerOFF, an international effort targeting DDoS-for-hire infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The October 16, 2024 indictment charged Ahmed Omer and Alaa Omer. Infrastructure seizure can disrupt an operation and expose its alleged administrators, but it does not automatically prove that every related Telegram channel, persona, affiliate, or later attack disappeared. Rebranding and replacement infrastructure remain possible in this type of ecosystem.

How to evaluate claims about Anonymous Sudan

Reports about the group often blend several kinds of evidence. A more reliable reading separates them into four levels:

  1. Self-claimed: what Anonymous Sudan said in Telegram posts.
  2. Observed: what researchers saw in language, infrastructure, targets, timing, and relationships.
  3. Vendor-attributed: what Microsoft, Mandiant, or another security company assigned to the activity.
  4. Law-enforcement allegation: what the DOJ indictment and FBI affidavit allege.

These categories are not interchangeable. A Telegram claim is weaker than a technical attribution; a technical attribution is different from an indictment; and an indictment is not a conviction.

So, was Anonymous Sudan Sudanese?

That depends on what “Sudanese” means:

  • Nationality: the DOJ alleges that the operators were Sudanese nationals.
  • Location: the FBI affidavit describes an investigation indicating Sudan-based leadership.
  • Political representation: the evidence does not show that the operation represented Sudanese society or the Sudanese government.
  • Independence from Russia: its KillNet relationship and Russia-aligned targeting argue against treating it as an isolated local movement.
  • Motivation: political messaging, commercial activity, and foreign-aligned narratives appear to have coexisted.

It is entirely possible for Sudanese operators to use Russian-language channels, work with a Russia-aligned group, and advance narratives useful to Russia. Nationality, location, political identity, and foreign influence are separate questions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the name means now

“Anonymous Sudan” should be treated as a public persona, a threat-intelligence label, and the name attached to an alleged criminal operation—not as a reliable statement of affiliation with Anonymous or of independent Sudanese political identity.

The early phrase “neither anonymous nor Sudanese” captured a genuine mystery: the group’s branding and Russian connections did not fit its stated identity. But later U.S. evidence changed the second half of that conclusion. The better account is more precise than the slogan.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.