CSIDB logo
Threat actor

Mr.Slyman

Attribution profile

Type
Activist
Location
Saudi Arabia
Known incidents
1 incident
First seen
2014-08-15
Last seen
2014-08-15
Updated
2026-07-31 22:23
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the alias Mr.Slyman. Open‑source reporting places Mr.Slyman’s location in Saudi Arabia. The only incident described in the provided material is the August 15 2014 defacement of the Saudi state TV website Alikhbaria by a group that identified itself as SYRIAN CYBER. The source material does not indicate that Mr.Slyman was involved in or claimed responsibility for that Alikhbaria incident. No information is given about the sectors or industries that Mr.Slyman typically targets. The documents do not describe any strategic objectives such as financial profit, espionage, or disruption for Mr.Slyman.

No malware families, exploit tools, or initial‑access vectors are mentioned in connection with Mr.Slyman. There is no publicly available attribution linking Mr.Slyman to a state‑sponsored program or a criminal consortium. Consequently, no specific campaigns, operations, or notable activities can be ascribed to Mr.Slyman based on the supplied sources. The provided article collection contains unrelated cybersecurity news items that do not reference Mr.Slyman at all. Therefore, any description of Mr.Slyman’s behavior beyond the alias and location would require external information not present here. This profile is limited to the confirmed facts presented in the prompt.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB