CSIDB logo
Threat actor

YMH

Attribution profile

Type
Activist
Location
Yemen
Known incidents
1 incident
First seen
2014-03-31
Last seen
2014-03-31
Updated
2026-07-31 07:35
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias YMH has been observed operating from Yemen. YMH’s activity is limited to a series of website defacements targeting Egyptian government institutions in March 2014. The first confirmed incident occurred on 31 March 2014 when the official site of the Egyptian Armed Forces Training Authority was compromised and its content replaced with a defacement page. The defacement message, written in Arabic and later translated, urged visitors to set aside political disputes and enjoy a cup of tea, reflecting a neutral stance rather than support for any faction. Prior to this, on 23 March 2014, the same actor defaced the websites of the Egyptian Tourist Development Authority and the Military Technical College with nearly identical wording. All three targets belong to the public sector, specifically governmental bodies responsible for training, tourism, and technical education.

The repeated use of similar defacement messages indicates a consistent strategic objective of disrupting online presence to convey an apolitical, humorous commentary. No evidence points to financial gain, espionage, or data theft; the actions appear aimed at publicity and message dissemination rather than profit or intelligence collection. The actor’s tactics, techniques, and procedures are confined to web defacement; no malware families, exploit kits, or specific tooling have been reported in the associated sources. Consequently, the initial access vector remains unspecified in the public record, though it likely involved exploiting a vulnerability in the web applications or server configurations. Attribution to a state sponsor, criminal syndicate, or hacktivist collective has not been established, and YMH operates without any publicly claimed affiliation. The March 2014 defacement campaign represents the entirety of YMH’s publicly documented operations, with no further incidents attributed to the alias in the available sources. Observers note that the defacements were limited to visual alteration of web pages and did not involve data exfiltration or persistent access to the compromised servers. Despite the simplicity of the technique, the incidents attracted media attention due to the high‑profile nature of the Egyptian governmental sites involved.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB