SultanHaikal
Attribution profile
- Type
- Sensationalist
- Location
- Indonesia
- Known incidents
- 3 incidents
- Sources
- 2 sources
- First seen
- 2014-01-15
- Last seen
- 2015-01-01
- Updated
- 2026-07-30 20:11
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
SultanHaikal, also known as Sultan Haikal, is an Indonesian hacker who operates under the handle SultanHaikal and is associated with the hacker group Gantengers Crew. The group’s origin is traced to Indonesia, and SultanHaikal has been publicly identified in multiple defacement incidents attributed to Gantengers Crew. He is not described as acting alone but rather as a member of this collective, which has claimed responsibility for several website defacements targeting international organizations. No state sponsorship or broader criminal consortium is mentioned in the available sources regarding his affiliation.
His activities have focused on online services and software companies, including cloud‑based file‑sharing platforms, cybersecurity training providers, and antivirus software distributors. The targets have spanned global services such as Ubuntu One, the International Council of E‑Commerce Consultants’ subdomains, and AVG’s distributor websites in Argentina, Bolivia, Chile, Uruguay, as well as AVG’s Japan‑hosted blog. SultanHaikal has explicitly stated that the motivation behind the Ubuntu One defacement was to demonstrate that nothing is fully secured, and the accompanying messages challenged the credibility of other hackers, indicating an aim to prove insecurity and garner notoriety rather than financial gain. The observed tactics involve uploading defacement HTML or image files through legitimate file‑sharing functions and directly compromising web servers to replace content with protest messages, without reference to malware families, exploit kits, or persistent access tools.
Representative operations include the January 2014 defacement of six Ubuntu One domains where SultanHaikal uploaded a defacement image via the platform’s file‑sharing service, the January 2014 compromise of eight AVG distributor websites in South America and the defacement of AVG’s Japan blog by a Pakistani accomplice, and the January 2015 defacement of multiple EC‑Council subdomains by Gantengers Crew that mocked the organization’s security training offerings. These incidents illustrate a pattern of website defacement intended to highlight perceived vulnerabilities and assert the group’s presence across different sectors and regions.
Incidents
Attributed incidents are available to members.
3 incidentsSources
Sources available to members: 2 sources.