Anonymous Norway
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Anonymous Norway, operating under an alias linked to the broader Anonymous collective, is the threat actor referenced in the reporting. The actor’s known targeting focuses on Norwegian financial institutions, exemplified by the July 2014 attacks against entities such as Evry, DNB, and Norges Bank. Those incidents affected more than eight financial companies simultaneously, indicating a broad sector impact. The actor’s stated motivation, as expressed in a message attributed to Anonymous Norway, was to raise public awareness about the rising frequency of IT security attacks and the perceived lack of preventive action. No additional financial, espionage, or geopolitical motives are specified in the source material.
The reported tactic involved exploiting a known vulnerability in the MailPoet WordPress plugin to generate malicious traffic directed at the victims’ servers. No specific malware families or custom tooling are described in the source; the attack relied on leveraging compromised web resources for traffic generation. According to Roar Thon, technical director of Norway’s National Security Authority, executing a DDoS attack requires only a credit card and the intent to cause disruption, indicating a low technical barrier. Attribution claims were made by Anonymous Norway via social media and email, yet the same account later denied responsibility and attributed the activity to unskilled script kiddies. No definitive link to a state sponsor or organized criminal consortium has been established in publicly available sources. The July 2014 distributed denial‑of‑service campaign against multiple Norwegian financial services remains the primary publicly referenced operation associated with this actor.
Incidents
Attributed incidents are available to members.
7 incidents