CSIDB logo
Threat actor

Daeshgram

Attribution profile

Type
Activist
Location
Iraq
Known incidents
5 incidents
First seen
2017-11-18
Last seen
2017-11-18
Updated
2026-07-30 20:57
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Daeshgram is the alias used by a group of Iraqi hackers who have been publicly identified in open‑source reporting. The actors are based in Iraq and have directed their activity toward the communication networks of the extremist organization known as the Islamic State (ISIS). Their primary focus has been on undermining the credibility of ISIS propaganda channels, particularly the Amaq news platform and associated Telegram groups, by introducing deceptive content and disrupting service availability. The stated strategic objectives of their operations are to sow distrust among ISIS supporters, provoke internal disputes, and create a sense of paranoia about the authenticity of shared material, rather than to pursue financial gain or espionage.

The threat actor’s tactics, techniques and procedures involve the creation of counterfeit websites that closely mimic the official Amaq news site, the insertion of pornographic imagery and mocking messages into fabricated announcements, and the deliberate flooding of those platforms with traffic to induce temporary outages. Prior to launching the campaign, the hackers reportedly studied the target sites for months to replicate their appearance and behavior. They also maintained a public Twitter account under the Daeshgram name to showcase their work and amplify the impact of their actions. No specific malware families, exploit kits, or initial access vectors are described in the available sources; the emphasis is on web‑based deception and traffic overload rather than malicious code deployment.

Attribution to any state sponsor or criminal consortium is not established in the reporting; the actors are described solely as Iraqi hackers operating under the Daeshgram moniker. The most notable and repeatedly referenced campaign occurred on 18 November 2017, when Daeshgram infiltrated ISIS communication channels by deploying fake Amaq sites laden with explicit content, overwhelming servers to disrupt access, and using social media to publicize the effort. This operation resulted in visible confusion within extremist circles, prompted members to question each other’s shared links, and led to the removal of individuals from propaganda forums as trust eroded. The incident remains the principal publicly documented activity associated with this threat actor.

Incidents

Attributed incidents are available to members.

5 incidents
CSIDB