Cyber Threat Actor: Aslan Neferler Tim
| Actor Type | Location | Known Incidents |
Activist
|
Turkey
|
4 incidents |
|---|
Profile
The threat actor known as Aslan Neferler Tim, also referred to as the Lion Soldiers Team, is a Turkish nationalist hacking collective that has publicly claimed responsibility for cyber operations against Austrian targets. The group describes its actions as a response to perceived attacks on Islam and the Turkish nation and cites political tensions stemming from Austria’s opposition to Turkey’s European Union membership ambitions, including the recall of Turkey’s ambassador to Vienna. Their stated focus has been on governmental and private entities within Austria, particularly those perceived as opposing Turkish interests.
The collective’s observed tactics include launching coordinated email‑flood campaigns designed to overwhelm server capacity, as demonstrated in the September 9 2016 operation against Austria’s National Bank where two successive waves of high‑volume email traffic were used to disrupt the bank’s online services. In an earlier incident on September 3 2016 the group claimed responsibility for a cyber‑attempt on the Vienna International Airport’s website, describing the act as a reaction to alleged racism by airport officials, although the attack was reported as unsuccessful by Austrian authorities. No specific malware families, exploit kits, or intrusion tools are mentioned in the open sources; the described activity centers on volume‑based traffic generation and website defacement or disruption attempts. Attribution in public reporting places the actor within a Turkish nationalist milieu, with no explicit linkage to a state sponsor or criminal consortium disclosed.
The two publicly documented campaigns illustrate a pattern of politically motivated disruption targeting Austrian infrastructure, with the group threatening further actions against both public and private organizations in the country. These incidents highlight how nationalist narratives can be translated into disruptive cyber operations without reliance on sophisticated malware, relying instead on volumetric tactics to achieve temporary service interruption. The actor’s activity remains confined to the geopolitical context of Turkey‑Austria relations, as reflected in the disclosed motivations and targets.
