CSIDB logo
Threat actor

Anonymous Arab

Attribution profile

Type
Activist
Location
Israel
Known incidents
8 incidents
First seen
2015-04-06
Last seen
2015-04-06
Updated
2026-07-31 21:30
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Anonymous Arab is a hacking group known by that alias and has been associated with the OpIsrael campaign. The group’s location is reported as Israel, though precise details are not publicly confirmed. Its activities have focused on Israeli entities across government, academic and commercial sectors. The attackers have sought to disrupt services by defacing websites and to obtain financial data by exfiltrating PayPal credentials. In addition to financial information, they have leaked email passwords, personal identification details and modem login credentials. These actions demonstrate a focus on disrupting services and obtaining sensitive data. The group operates as part of a larger collective that includes Anonymous, AnonGhost and Anonymous Arabe. No direct state sponsorship or criminal‑enterprise affiliation has been established in open sources. The group’s public statements frame the activity as a protest operation under the OpIsrael banner. Their targeting is limited to Israeli online portals and services that hold sensitive citizen and business data.

The most documented operation attributed to Anonymous Arab occurred on April 6 2015 as part of OpIsrael. During that campaign the group claimed responsibility for compromising roughly seven hundred Israeli websites. Attackers exfiltrated over two thousand PayPal account credentials, more than seven thousand email‑password pairs and personal data for approximately one hundred fifty thousand individuals. Modem login information for six thousand devices was also disclosed. The stolen data was published on paste sites such as Pastebin and Ghostbin, and the authenticity of the leaked material was verified by analysts. Defaced sites were listed in public pastebins, showing a pattern of website alteration alongside data leakage. The reporting does not mention any specific malware families, exploit kits or initial‑access vectors. The activity is described as involving website defacement and the publication of stolen data. The group’s association with Anonymous, AnonGhost and Anonymous Arabe indicates a collaborative relationship under the OpIsrael banner. This 2015 OpIsrael incident remains the primary publicly referenced example of Anonymous Arab’s activity.

Incidents

Attributed incidents are available to members.

8 incidents
CSIDB