Cyber Threat Actor: Anonymous
| Actor Type | Location | Known Incidents |
Activist
|
Italy
|
34 incidents |
|---|
Profile
Anonymous is a hacktivist collective known by the alias Anonymous, with a reported presence in Italy. The group has been linked to operations targeting government bodies, private companies and critical infrastructure across several countries, including Brazil, Italy, Russia and Lithuania. Observed objectives include disrupting services through denial‑of‑service actions, causing financial harm by altering transactional data, leaking internal communications to expose perceived wrongdoing, and broadcasting political messages to advance social or ideological causes. These activities are consistently described as hacktivist rather than financially motivated, with the actors stating goals such as demanding inquiries into social issues, supporting pro‑Ukraine narratives, or opposing perceived authoritarian regimes. The sectors most frequently hit are municipal administrations, legislative assemblies, customs and logistics firms, research institutes, vending‑machine manufacturers and alcohol distribution networks, indicating a focus on both public‑service entities and privately operated critical infrastructure.
The tactics observed in the reported incidents rely heavily on distributed denial‑of‑service attacks that overwhelm web services and render them unavailable. In several cases the group has exploited misconfigured Docker installations exposed via public APIs to hijack computational resources and amplify DDoS traffic against government, military and media targets. Intrusions into internal networks have been achieved by compromising central servers, as seen in the attack on an Italian vending‑machine manufacturer, which allowed the actors to manipulate pricing and display political slogans on thousands of distributed devices. Data exfiltration has been carried out using standard file transfer methods, with the stolen material subsequently published on the DDoSecrets platform to maximize public impact. No specific malware families are mentioned in the source material, and the tooling appears to consist of readily available scripts and configuration abuse rather than custom malware. Some operations also involved the simultaneous manipulation of thousands of geographically dispersed nodes to enforce price changes or convey messages.
Anonymous is frequently associated with other pro‑Ukraine hacktivist collectives, notably the Ukraine IT Army, and its actions are framed as part of the broader #OpRussia campaign that emerged after the 2022 invasion of Ukraine. This affiliation is evident in coordinated operations against Russian entities such as the Federal Research Institute of Fisheries and Oceanography, the customs broker ALET, and the alcohol distribution system, where large volumes of email data were exfiltrated and leaked. Representative operations include the 2023 attempt against the Câmara Municipal de Salvador in Brazil, which was motivated by demands for a national inquiry into sexual harassment in schools, and the 2023 compromise of the Italian vending‑machine manufacturer that forced discounted sales and displayed anarchist‑themed messages. Additional examples are the 2022 DDoS against the Kamchatka Legislative Assembly, the 2022 leak of 466 GB from the Polar Branch of the Russian fisheries institute, and the 2022 disruption of the Russian alcohol distribution system via Docker‑based resource hijacking. Together these examples illustrate the group's pattern of mixing disruptive techniques with information leaks to pursue political and social objectives.
