CSIDB logo
Threat actor

YourVikingdom2015

Attribution profile

Type
Activist
Location
United States of America
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-28 15:38
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor operates under the aliases @YourVikingdom2015 and YourVikingdom2015, with a known presence on Twitter where they posted under the handle @YourVikingdomon. Public reporting places the actor’s activity within the United States, specifically noting an attack on the Indiana state government website. The actor describes itself as a group rather than an individual, and its online persona has been used to claim responsibility for multiple incidents. No further personal details or organizational structure are disclosed in the source material.

The actor’s observed targeting focuses on government entities at the state, local, tribal, and territorial levels, all located within the United States. The strategic objective demonstrated in the reported incidents is disruption, achieved through distributed denial‑of‑service attacks that overwhelm victim websites with traffic. The actor has stated that the attacks are carried out for entertainment or fun, rather than for financial gain, espionage, or ideological commitment. Technical details reveal that the actor exploits weak or absent DDoS protections, flooding the target with sufficient traffic to cause service outages, as seen when the Indiana site went offline for approximately forty‑five minutes before restoration. No specific malware families, exploit kits, or initial access vectors are mentioned in the reporting.

A representative campaign occurred in March 2015 when the actor knocked down the Indiana state website (in.gov) following the signing of a controversial religious freedom bill, claiming responsibility via Twitter and noting that they had also taken down another thirty‑four state, local, tribal, and territorial government websites earlier that month. The attack was described as a response to online protest but the actor later indicated that the bill served merely as a pretext, with the underlying motivation being the ease of exploiting poorly defended sites. After the incident, the Indiana Office of Technology examined the outage, the website was restored, and the actor’s Twitter handle was subsequently suspended. No additional publicly attributed operations or affiliations with state sponsors or criminal consortia are documented in the available sources.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB