CSIDB logo
Threat actor

AnonymousGlobo

Attribution profile

Type
Activist
Location
China
Known incidents
4 incidents
First seen
2015-04-10
Last seen
2023-10-01
Updated
2026-08-01 01:52
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the aliases AnonymousGlobo and Anonymous64 and is publicly linked to the Anonymous hacktivist collective. Open‑source reporting places the actor’s location in China, although no more specific geographic detail is provided. The actor’s activity is described as politically motivated hacktivism, with public statements tying actions to solidarity with protest movements and criticism of government policies. No credible sources have identified a state sponsor or a criminal consortium behind the actor’s operations. The actor maintains a visible online presence, most notably a Twitter handle @AnonymousGlobo that has been cited in multiple intrusion reports.

In October 2023 the actor compromised Macau Radio Taxi Services, a transportation operator in Macau, to display unauthorized graphics on in‑vehicle screens that referenced mainland Chinese social issues such as youth unemployment and flood relief efforts while displaying the tagline “Hacked by Anonymous64”; the company characterized the incident as a national security threat and reported it to law enforcement. In April 2015 the actor breached the Baltimore Police Department’s servers in the United States, leaking email addresses and internal IP addresses related to webmail and mapping services onto Pastebin, a disclosure that could enable phishing or distributed denial‑of‑service attempts against the department. Also in April 2015 the actor defaced the Hunan Police Academy website and other Chinese government sites with messages condemning the authorities’ suppression of Hong Kong pro‑democracy protests. Concurrently, distributed denial‑of‑service attacks were launched against numerous Chinese government websites, disrupting access to those services. A separate surveillance effort employed a malicious Android application disguised as an #OccupyCentral app to track the movements of Hong Kong protesters. Earlier, in 2014, the actor participated in a campaign that shut down several Chinese government websites in support of the same protest movement, demonstrating a pattern of targeting state‑aligned online infrastructure during periods of civil unrest.

The actor’s observed tactics include website defacement, distributed denial‑of‑service flooding, leakage of sensitive data via public paste sites, deployment of malicious mobile applications for surveillance, and compromise of specialized display systems such as those found in taxis, although the exact initial access vectors for these incidents are not detailed in the sources. These tactics have been grouped under publicly referenced operations such as OperationChina for the 2015 Chinese government actions, the Baltimore Police Department data leak, the 2023 Macau Radio Taxi incident, and the 2014 Chinese website shutdown campaign. No evidence points to financial gain as a primary motive; instead the actor’s actions appear aimed at disruption, propaganda, and intelligence gathering in support of perceived social causes. The actor remains active, with its aliases continuing to appear in claims of responsibility for politically charged cyber incidents.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB