The Horsemen Of Lulz
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Horsemen Of Lulz is a threat actor known by that alias and has been linked to the United Arab Emirates in open sources. They operate in close association with the hacking group NullCrew, often coordinating joint operations under the NullCrew FTS banner. Their publicly stated focus is on media megacorporations, aiming to cause disruption and public embarrassment as part of a broader campaign to “bring pain” to those entities. This targeting aligns with their observed activity against major Middle Eastern broadcasters and large telecommunications firms that also serve media audiences. The actor’s geographic base in the UAE informs their regional interest, though they have demonstrated the ability to strike targets beyond that area when opportunities arise.
Their tactical approach centers on exploiting known, unpatched vulnerabilities in externally facing services rather than deploying custom malware. In the Al Arabiya intrusion they leveraged CVE‑2013‑7091, a Zimbra mail server flaw for which a patch had been available since December 2013, to gain initial access. Once inside, they harvested credentials directly from the server’s localconfig.xml file, exposing email passwords and potentially compromising linked accounts. The group then disclosed the breach via Pastebin, sharing details of the compromised servers and the exploit used to shame the victim and warn other organizations. No specific malware families or custom tooling are referenced in the available reporting, indicating a reliance on legitimate administrative tools and credential‑theft techniques after the initial vulnerability exploit.
Notable operations include the April 2 2014 compromise of Al Arabiya, a major Middle Eastern news outlet, conducted jointly with NullCrew, and the earlier February 9 2014 breach of Comcast’s servers, also carried out with NullCrew using the same Zimbra vulnerability. In both cases the actors highlighted the victims’ failure to apply a known patch, extracted sensitive authentication data, and made the findings public to increase pressure on the targets. These incidents illustrate a pattern of targeting organizations with outdated internet‑facing applications, harvesting credentials for impact, and using public disclosure as a means to achieve their disruption‑oriented objectives against media‑related sectors.
Incidents
Attributed incidents are available to members.
1 incident