Cyber Justice Team
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Cyber Justice Team, also known by its alias, is a hacktivist group that has been linked to operations originating from Syria. The group publicly identifies itself as opposing both the Assad regime and ISIS, framing its actions as a protest against what it describes as the destruction of the Syrian people by those entities. In April 2016 the Cyber Justice Team claimed responsibility for a large‑scale compromise of Syrian government and private websites, exploiting known vulnerabilities in the Joomla content management system that powered many of the targeted portals. The attack resulted in the exfiltration and public release of approximately 43 gigabytes of data, which after decompression amounted to 274,000 files drawn from 55 distinct domains, roughly half of which were .gov.sy government sites. The leaked material included server passwords, MySQL host permissions, administrative credentials, older shell files, and database entries that reflected both newly obtained information and remnants from prior intrusions. The group stated that it deliberately removed any files related to the government‑run education system and children’s hospital to avoid exposing civilian information, a detail highlighted in its post‑hack communications on Twitter.
The April 6 2016 incident represents the most prominently documented operation attributed to the Cyber Justice Team, serving as a representative example of its typical targeting and tactics. The attackers relied exclusively on exploiting outdated Joomla vulnerabilities, noting that the platform had a history of frequent disclosures and that the targeted organizations had not applied available patches. By leveraging these known weaknesses they were able to gain access to web portals, harvest credentials, and assemble a data set that combined fresh breaches with historical artifacts such as older shell files and injection attempts. The stolen data was subsequently posted on Pastebin, making it publicly accessible. Throughout the operation the group emphasized the systemic negligence of maintaining up‑to‑date web infrastructure, pointing out that the ease of the compromise underscored how outdated content management systems can be leveraged for relatively simple intrusions against government assets. No other campaigns or affiliations are described in the available sources, and the profile is limited to the facts presented in the reported incident and accompanying analysis.
Incidents
Attributed incidents are available to members.
2 incidents