Fallaga Team
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor referenced in the source material is a Tunisian Islamist hacktivist group that refers to itself as the Fallaga Team, also appearing in reports as the Tunisian Fallaga Team or Tunisian Fallaga Team. The group publicly claimed responsibility for hundreds of websites around the world overseen under the alias Fallaga Team, also referenced in the articles as the Tunisian Fallaga Team. The group has claimed responsibility for compromising hundreds of websites worldwide overarch as noted in an October 2015 report. They describe themselves as Islamist hacktivists motivated by perceived grievances against Western actions and Islamophobia, a self‑description that appears in the messages they leave on compromised sites.
Their targeting pattern, as evidenced in the sources, includes repeated attacks on Jewish educational institutions such as the Jewish Free School (JFS) in North London and the Bnos Yisroel day school in Baltimore, Maryland. Following the January 2015 they defaced the website of the open‑source text editor Notepad++ after the developer released a “Je suis Charlie” edition, posting anti‑Western statements on the defaced page. After the January 2015 Charlie Hebdo shooting in Paris they focused their efforts on French‑hosted websites regardless of the site’s sector, leaving messages that condemned perceived aggression against Muslims and called for an end to Islamophobia. The group’s posted rhetoric includes the exact phrase “You made the terrorism and you occupate our country,” which they used to frame their actions as a response to perceived foreign oppression.
Observed tactics, techniques and procedures described in the material are limited to website defacement and the placement of political messages on the compromised pages. No specific malware families, exploit kits, or intrusion vectors are mentioned in the sources; the group’s activity is characterized by the alteration of web content to disseminate their statements rather than the deployment of persistent malware or espionage tools. Their operational style appears to rely on exploiting publicly accessible web assets to achieve visibility for their messaging.
Attribution details provided by the reporting are confined to the group’s self‑identified Tunisian Islamist hacktivist nature; no explicit link to a state sponsor, criminal syndicate, or broader terrorist organization is presented in the sources. Consequently, any assertion about state direction or criminal affiliation would be speculative and is omitted here. The group’s public statements and the geographic focus of their defacements suggest a Tunisian origin, but this is treated as a self‑described attribute rather than an independently verified assessment.
Notable campaigns highlighted in the material include the defacement of JFS’s website in North London, the compromise of Bnos Yisroel in Baltimore, the Notepad++ incident tied to the “Je suis Charlie” release, and a series of French‑oriented website defacements that began shortly after the January 2015 Charlie Hebdo attack. Each of these actions involved the replacement of legitimate site content with the group’s political messages, demonstrating a repeated use of web‑defacement as a means to broadcast their viewpoint to a broad audience. The cumulative effect of these operations, as described in the sources, is a pattern of ideologically motivated website vandalism targeting perceived symbols of Western or Jewish interests.
Incidents
Attributed incidents are available to members.
4 incidents