Islamic State Hackers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Islamic State Hacker operates under that alias and has been linked to activities originating from China. The actor uses the moniker Islamic State Hacker to claim affiliation with the militant organization Islamic State. Public reporting identifies the actor as being based in China, although no further detail about infrastructure or personnel is available. The actor’s public persona is built around proclaiming support for jihad through online actions. No other aliases are documented in the supplied material. The actor’s activity has been observed in open‑source reports dating from 2015 to 2016.
Observed targeting includes diplomatic missions and educational institutions, specifically the Turkmen embassy in Belarus and Tsinghua University in China. The actor’s actions have been confined to website defacement, which serves to disrupt normal service and to broadcast a propaganda message. In both cases the defaced pages featured imagery and audio or text endorsing holy war, indicating a strategic objective of ideological promotion rather than financial gain. The messages were delivered in English and, in the embassy case, also in Russian to reach a broader audience. The Turkmen embassy incident resulted in the site becoming inaccessible, with no official comment issued by the diplomatic mission. No evidence points to espionage, data theft, or monetary extortion in these incidents.
The April 2015 defacement of the Turkmen embassy website in Minsk involved the actors identifying themselves as Abdellah Elmaghribi and Moroccan Wolf under the banner ISLAMIC STATE HACKERS (El Moujahidine). The January 2016 incident saw Tsinghua University’s site altered to display a photograph and audio supporting jihad, accompanied by the statement Everything is OK in the end. If it’s not OK, then it’s not the end. These two operations are the only publicly reported campaigns attributed to the actor in the provided sources. Attribution to any state sponsor or criminal consortium has not been established; the actor’s claims of Islamic State affiliation remain unverified by independent verification. Both defacements were reported by news outlets such as RFE/RL and the South China Morning Post, which provided the primary source material. The actor’s activity appears limited to high‑visibility web defacements intended to spread extremist messaging.
Incidents
Attributed incidents are available to members.
1 incident