Turkish Cyber Army
Attribution profile
- Type
- Nation State
- Location
- China
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2018-07-10
- Last seen
- 2018-07-10
- Updated
- 2026-08-01 01:27
- Aliases
- 3 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases Turksiberkarargh, Turk Siber Karargah and Turkish Cyber Army has been referenced in open‑source reporting as operating from China, although the exact geographic base is not independently verified beyond that note. The actor first came to public attention in July 2018 when a Cambodian human rights organization reported that its website had its site displaying a false maintenance message and the claim that the site was being worked on, and the group Adhoc explicitly named the hacker as Turksiberkarargh in its statement. This incident was described as a website defacement rather than a data‑theft operation, but it occurred amid a broader series of cyber intrusions reported against Cambodian institutions.
Targeting observed in the available sources includes non‑governmental organizations, government ministries, the national election committee, opposition political parties and the ruling party, all located in Cambodia. The activity coincided with a reported espionage campaign that a U.S. cybersecurity firm assessed was being carried out on behalf of the Chinese state, although the firm’s assessment concerned a separate group called TEMP.Periscope. Analysts commenting on the campaign suggested that the intrusions were aimed at gathering intelligence that could be used to understand the political climate and potentially influence the forthcoming general election, noting that data had been taken from both opposition and ruling party sources. No mention of financial gain or profit‑making motives appears in the reporting, and the actor’s objectives are therefore described solely in terms of information collection and possible electoral influence.
The tactics, techniques and procedures described are limited to website defacement with a deceptive maintenance notice and unauthorized access to computer systems belonging to government and political entities; specific malware families, initial‑access vectors or tooling styles are not disclosed in the sources. Attribution to a state sponsor is not directly asserted for the actor using the Turksiberkarargh alias, but the concurrent activity was linked by analysts to the TEMP.Periscope group, which a U.S. firm assessed with high confidence as working on behalf of the Chinese government, while Chinese officials denied involvement. The most notable publicly reported operation involving this alias is the July 2018 defacement of the Adhoc website in Cambodia, which took place alongside the wider espionage effort targeting electoral bodies, ministries, NGOs and political parties ahead of the country’s July 29 general election. This case remains the primary concrete example of the actor’s activity in the open record.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.