CSIDB logo
Threat actor

AnonSec

Attribution profile

Type
Activist
Location
Palestine
Known incidents
5 incidents
First seen
2013-01-01
Last seen
2016-01-01
Updated
2026-07-31 02:52
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Anoncoders (also referenced as Anoncoders or AnonCoders) is a self‑identified hacktivist group that describes its members as Palestinian hackers opposed to Zionism and insists it operates independently of the Anonymous collective. Members first appeared in public reporting in October 2015 when they defaced the website of Radio Tel Aviv, posting a message that read “We are always here to punish you” and declaring their main target as Zionism and Israhell. The group has used the Guy Fawkes mask in some defacements but explicitly states that it refuses collaboration with Anonymous members. No public source has linked the organization to a state sponsor or to a criminal syndicate.

The group’s observed targets include Israeli media outlets, United States political party websites, a French television broadcaster, and a United States synthetic‑turf company, indicating activity across Israel, the United States, and France. Their stated motivation is to disseminate political messages rather than to pursue financial gain or conduct espionage, with members claiming they aim to counter the perception that Muslims spread terrorism by asserting that governments are the true terrorists. Their actions are characterized as hacktivist vandalism intended to convey ideological statements to governments and the broader public.

The primary technique observed in their operations is website defacement, wherein the main page of a target is replaced with a political message and often accompanied by the Guy Fawkes mask image. Defacements serve as a vehicle for statements such as the “We are always here to punish you” notice placed on Radio Tel Aviv’s site. The group has claimed responsibility for disrupting the broadcast of the French television network TV5Monde, although they downplay the sophistication of that operation relative to other attacks. No specific malware families, exploit kits, phishing vectors, or custom tools are mentioned in the source material, indicating a reliance on web‑based defacement methods and broadcast interference capabilities.

The actors self‑identify as Palestinian hackers and deny any affiliation with Anonymous or state actors, and no credible public source has attributed them to a government intelligence service or a criminal consortium. Representative operations include the October 2015 defacement of Radio Tel Aviv’s website and the May 2015 defacement of the Republican Party of Kentucky’s site, which remained visible from Saturday afternoon until mid‑Tuesday. They also reference involvement in the April 2015 TV5Monde broadcast interruption, describing it as less complex than the Kentucky GOP defacement. Additional defacements have been noted against a Nashville synthetic‑turf company and other targets archived on the Zone‑h defacement repository.

Incidents

Attributed incidents are available to members.

5 incidents
CSIDB