Algerian digital militias
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Algerian digital militias is the alias used to describe a threat actor operating from Algeria. The group has been identified in open‑source reporting as responsible for cyber actions against neighboring states. Public sources indicate that the actor’s activities are primarily conducted from within Algerian territory. No further details about the organization’s structure, size, or internal hierarchy are available in the referenced material. The alias reflects a self‑described militant orientation rather than a formal corporate or criminal entity.
In the only publicly documented incident, the actor targeted Moroccan government websites, specifically the ministries of Agriculture, Employment, and Parliament Affairs, as well as the Economic Inclusion and Small Business portal. The attack was a distributed denial of service operation that employed a Kill Chain approach, according to analysts who attributed the activity to Algerian actors. The timing of the assault occurred late at night, a period when staffing levels are typically reduced, which likely contributed to its effectiveness. The prolonged disruption raised concerns about the affected sites’ visibility on search engines, indicating an objective of sustained service interruption rather than data theft or financial gain. No specific malware families, initial access vectors, or tooling styles were described in the source, so the only confirmed TTP theme is the use of volumetric DDoS traffic. Attribution is based on expert analysis that points to Algerian responsibility, but no explicit state sponsorship or criminal consortium links have been established in the reporting. The 2025‑04‑12 DDoS campaign against Moroccan government services remains the sole representative operation cited in the available information.
Incidents
Attributed incidents are available to members.
1 incident