CSIDB logo
Threat actor

Crazy-3r3r

Attribution profile

Type
Activist
Location
Saudi Arabia
Known incidents
2 incidents
First seen
2015-08-21
Last seen
2016-01-22
Updated
2026-08-01 05:51
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the aliases Mr.Xpr! and Crazy‑3r3r and is publicly associated with Saudi Arabia. Their activity has focused on governmental web portals in the Middle East, specifically targeting Iranian and Saudi state‑related sites. The observed actions are not driven by financial gain but appear to serve political protest objectives, such as opposing Saudi‑led military operations in Yemen and reacting to the execution of a prominent Shiite cleric. These defacements aim to convey a message and disrupt the normal operation of the targeted online presence rather than to steal data or generate profit.

In terms of tactics, the actor relies on web defacement techniques, replacing site content with protest images or text statements, and has not been linked to any specific malware families or sophisticated intrusion tools. Mr.Xpr! has been identified as a member of the Iran Hack Security Team, while Crazy‑3r3r has previously defaced UAE police websites, indicating a pattern of targeting security and government infrastructure. Notable operations include the 2016 defacement of Iran’s Supreme Leader blog, where a Saudi fighter jet image was posted, and the 2015 intrusion on the Royal Saudi Air Force website that left the message “Hacked By Mr.Xpr! Iran Hack Security Team” to protest the Yemen campaign. These incidents illustrate the actor’s role in the broader cyber exchanges between Iranian and Saudi affiliated groups.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB