CSIDB logo
Threat actor

GeNiuS-JorDan

Attribution profile

Type
Activist
Location
Jordan
Known incidents
1 incident
First seen
2016-01-06
Last seen
2016-01-06
Updated
2026-07-31 22:05
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

GeNiuS‑JorDan is the online alias used by a hacker who is publicly known to be based in Jordan. The actor first gained attention in early 2016 when the official website of the Republic of Uganda’s Ministry of Foreign Affairs and the High Commission sites representing Uganda in twenty different countries were defaced. The defacement replaced the original content with anti‑war messages that criticized United States military actions in Iraq, Afghanistan and Palestine and embedded a YouTube video featuring activist Dr. Dahlia Wasfi. Prior to this incident the same alias had been linked to breaches of Kuwaiti governmental systems, Iraqi customs authorities, Nepalese passport control services and parliamentary websites, indicating a pattern of targeting government‑related online assets.

The actor’s tactical approach appears to rely on gaining an initial foothold through a compromised ministry or diplomatic site and then deploying a mass defacement script to propagate the change across affiliated servers. No specific malware families, exploit kits or custom tooling are mentioned in the available reports; the emphasis is on the use of a script designed to replace web pages with political statements. The apparent strategic objective of the operations is to convey a political viewpoint rather than to pursue financial gain, espionage or sustained disruption, as the messages are explicitly anti‑war and the sites were restored after the defacement.

Public attribution does not connect GeNiuS‑JorDan to any state sponsor, criminal consortium or organized hacking group; the actor is described solely as an individual hacker operating from Jordan. The Uganda Ministry of Foreign Affairs incident stands as the most extensively documented campaign, while the earlier defacements of Kuwaiti, Iraqi and Nepalese government sites serve as additional examples of the actor’s recurrent focus on governmental domains to disseminate hacktivist content. All affected services were reported to have been returned to normal operation following each event, and no further technical details about persistence mechanisms or post‑exploitation activities have been disclosed in the sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB