Group_Dmar
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Group_Dmar is a threat actor known by that alias and has been associated with Kuwait based on the available reporting. The actor first came to public attention through a website defacement incident involving the Kuwaiti parliament’s official site. No other aliases or geographic details are provided in the source material.
The actor’s known activity consists of defacing the Kuwaiti parliament website on the day of parliamentary elections in November 2016. The defacement displayed a message in Arabic that accused a specific member of parliament of acting as an Iranian agent, threatened to release alleged secret communications involving Iranian and Syrian officials, and urged fellow lawmakers to oppose the accused individual. The message also called for parliamentary action to address the plight of stateless Bidoon residents, noting their lack of access to education and healthcare, and referenced a Saudi Arabian red line that should not be crossed. These elements indicate a politically motivated objective aimed at influencing domestic discourse and exerting pressure on governmental officials rather than financial gain or espionage.
The reported technique employed by Group_Dmar was website defacement; no malware families, specific initial access vectors, or particular tooling styles are described in the sources. Public attribution to a state sponsor, criminal consortium, or other affiliations has not been established. The November 2016 parliament defacement remains the sole publicly reported operation linked to Group_Dmar, serving as the primary example of their activity.
Incidents
Attributed incidents are available to members.
2 incidents