Cyber Threat Actor: Anti-Armenia Team
| Actor Type | Location | Known Incidents |
Activist
|
Azerbaijan
|
41 incidents |
|---|
Profile
The threat actor is publicly known as the Anti‑Armenia Team, also referred to as the Anti‑Armenian Team, and open‑source reporting associates the group with Azerbaijan. The actors have described themselves as an independent collective that has been active for several years, citing a five‑year history in their own statements to journalists. Their activity has been documented in multiple incidents ranging from 2014 through 2016, showing a pattern of operations directed against Armenian governmental and diplomatic targets.
The actor’s observed tactics include the defacement of websites, the hijacking of social media accounts, and the exfiltration of sensitive data. In several campaigns they replaced the content of Armenian presidential, ministry, and diplomatic mission pages with propaganda messages and videos that highlighted Azerbaijani military capabilities. They also compromised the official Twitter account of the Russian Embassy in Armenia, posting protest‑related messages and displaying an Azeri flag. A notable data leak involved passport scans of foreign visitors to Armenia and internal analytical reports from the Armenian National Security Service, which security experts confirmed as genuine but suggested may have originated from a compromised insider rather than a direct technical breach.
Representative operations include the September 2016 leak of Armenian government documents, the April 2016 takeover of the Russian Embassy’s Twitter account, and the coordinated January 2016 defacement of Armenian diplomatic sites linked to NATO, the OSCE, and the United Nations across roughly forty countries. Earlier actions in 2014 saw the group deface the Armenian presidential website and various ministry sites, often accompanied by video statements from Azerbaijani officials. These incidents demonstrate a recurring focus on Armenian state infrastructure and affiliated international missions, with the actor claiming responsibility and referencing prior actions by Armenian hacking groups such as the Monte Melkonian Cyber Army. The actor’s activities have been reported to cease temporarily after delivering their messages, after which the affected accounts or sites were restored.
