CSIDB logo
Threat actor

Dohaeragon

Attribution profile

Type
Sensationalist
Location
Turkey
Known incidents
0 incidents
Sources
1 source
First seen
-
Last seen
-
Updated
2026-07-30 21:43
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Dohaeragon is the alias used by a group that identifies itself as Team Faceless Men, a name drawn from the Game of Thrones universe. Publicly available information indicates that at least some members of the group are based in Turkey, with one identified member, Morghon, described as a 17‑year‑old male from Kusadasi. The actor has no recorded history on major defacement mirrors such as Zone‑H and is known primarily from a single appearance on a Turkish web site, golgeler.net. Their activity to date consists of website defacements that incorporate Game of Thrones themes, including references to Valar Dohaeris and the Faceless Men, and the use of the song “Hear Me Roar” as an accompaniment to the hacked page. These details suggest that the group's immediate objective is to demonstrate capability and express fandom rather than to pursue financial gain, espionage, or other strategic aims.

The most clearly documented operation attributed to Dohaeragon occurred in July 2018 when the group defaced Kaiser Permanente’s Health Innovations site (healthinnovation.kp.org). The defacement replaced the legitimate content with a message stating “Hacked by Dohaeragon” and embedded a link to a YouTube video of the Game of Thrones‑inspired track. The article notes that the targeted site had not been subjected to Kaiser Permanente’s usual security measures and had remained unpatched for an extended period, which likely facilitated the initial access. After the defacement, Kaiser Permanente restored service by moving the site to a different IP address, though it is unclear whether the underlying vulnerability was patched. The organization later confirmed that the externally hosted site contained no protected health information and that no member data was at risk. This incident remains the sole publicly reported campaign linked to the alias Dohaeragon.

Incidents

Attributed incidents are available to members.

0 incidents

Sources

Sources available to members: 1 source.

CSIDB