SaLeM
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
SaLeM is a threat actor known by that alias and has been linked to operations originating from the United States of America. The group first came to public attention in August 2014 when it defaced the Delaware Treasury Division website, replacing its content with anti‑Israel and pro‑Palestinian statements related to the Gaza conflict. This act was described by officials as a symbolic message rather than an attempt to steal data or achieve financial gain, indicating a political motivation rooted in the broader Israeli‑Palestinian discourse. Targeting appears focused on United States government‑affiliated web properties that rely on third‑party hosting services, as the Treasury site was managed by an external provider rather than state‑run infrastructure. The strategic objective demonstrated in the incident was disruption through website alteration to broadcast a ideological viewpoint, with no evidence of espionage, fraud, or revenue‑seeking behavior.
The actor’s tactics, techniques and procedures are limited to the exploitation of known security flaws in third‑party web hosting platforms to gain unauthorized access and modify site content. No malware families, custom tools, or sophisticated payloads were reported in the Delaware Treasury case; the intrusion relied solely on leveraging existing vulnerabilities to upload defacement pages and political messages. This method aligns with a broader pattern noted by state security officials, who observed that multiple websites across the United States suffered similar defacements during the same period, suggesting a campaign‑level use of the same initial access vector. No additional tooling, persistence mechanisms, or post‑exploitation activities were described in the available sources.
Attribution of SaLeM to any state sponsor, criminal consortium, or organized hacking collective has not been established in public reporting; the group self‑identified in the defacement message but no further links to known threat‑actor clusters have been disclosed. Consequently, any assertions about affiliations, funding, or hierarchical structure remain unsupported by the evidence presented in the incident reports.
A representative operation that illustrates the actor’s behavior is the August 18 2014 defacement of the Delaware Treasury Division website, which was restored within hours after detection and confirmed to involve no data theft. This incident exemplifies the group’s focus on using web‑site alteration as a means to convey political statements, and it fits within the observed series of comparable defacements targeting U.S.‑based entities that share reliance on external hosting arrangements.
Incidents
Attributed incidents are available to members.
1 incident