CSIDB logo
Threat actor

MuhmadEmad

Attribution profile

Type
Activist
Location
-
Known incidents
5 incidents
Sources
3 sources
First seen
2014-01-02
Last seen
2016-05-26
Updated
2026-08-28 17:24
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

MuhmadEmad, also known under the collective name KurdLinux_Team, is a hacker alias that has been linked to a series of website defacements carried out in support of Kurdish political causes and opposition to the Islamic State. The actor has claimed affiliation with KurdLinux_Team and has previously been associated with the broader Anonymous Kurdistan movement, indicating a loose network of activists rather than a formal criminal or state‑sponsored group. Targeting has spanned technology firms, local law‑enforcement agencies, cultural institutions and national government bodies, with compromised sites observed in the United States, Turkey and various European domains such as those belonging to Dell’s Entrepreneur‑in‑Residence program. The primary observable objective of these actions is disruption, as the defacements rendered the affected websites inaccessible while displaying political messages that included Kurdish symbols, anti‑ISIS rhetoric and criticism of Turkish government policies.

The actor’s tactics consistently involve exploiting known vulnerabilities in the Drupal content management system to gain unauthorized access to web servers, after which the original content is replaced with a defacement page. Proof of the compromises is routinely posted to the Zone‑H mirroring service, and the actor has recorded and uploaded walkthrough videos of the altered sites to YouTube to amplify the message. Each defacement page typically contains a Kurdish flag, a contact e‑mail address, and a statement that combines praise for Kurdish forces with condemnation of ISIS and, in some cases, Turkish authorities. No malware families, exploit kits or specialized tooling beyond the use of publicly available web‑application vulnerabilities have been reported in the associated sources.

Among the most widely reported operations, MuhmadEmad defaced five Dell subdomains (eir.dell.com, eir.dell.fr, eir.dell.ie, eir.dell.co.uk and eir.dell.nl) in May 2016, leaving anti‑Turkey and anti‑ISIS messages and linking the act to a YouTube video of the compromised pages. In August 2015 the actor targeted the Etowah County Sheriff’s Office and the Hardin Center in Alabama, displaying a Kurdish flag and a profane anti‑ISIS statement before the sites were temporarily taken offline and later restored. Earlier, in January 2014, the hacker—then operating under the Anonymous Kurdistan banner alongside MuhmadEmad—breached two Turkish government websites managed by the Afyonkarahisar Provincial Disaster and Emergency Management agency, posting a depiction of the Turkish prime minister as a dictator and demanding an end to alleged Turkish support for ISIS. These incidents illustrate a pattern of politically motivated website defacements aimed at disrupting online services while broadcasting a consistent pro‑Kurdish, anti‑ISIS narrative.

Incidents

Attributed incidents are available to members.

5 incidents

Sources

Sources available to members: 3 sources.

CSIDB