AgainstTheWest
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
AgainstTheWest is a hacking group that operates under the alias AgainstTheWest and has been referenced in open‑source reports as possibly based in China. The group describes itself as a hacktivist collective that claims to target countries and companies it perceives as hostile to Western interests. It has presented its activities as part of broader hacktivist campaigns such as #OpRussia, which aim to disrupt entities associated with the Russian state amid geopolitical tensions. The group’s public statements emphasize a motive of exposing information rather than pursuing financial gain.
The group’s reported targeting spans technology and energy sectors, with claims of compromising Chinese platforms TikTok and WeChat as well as Russian organizations including the GRU, Gazprom, Lukoil and Rosatom. It has asserted that its actions are intended to disrupt adversarial infrastructure and to leak internal data such as password hashes, internal project reports and testing environment screenshots. These activities are framed as hacktivist disruption and information exposure, consistent with the group’s alignment with anti‑Western and anti‑Russian narratives. No explicit financial or espionage objectives are stated in the source material.
Observed tactics, techniques and procedures include the alleged use of an Alibaba cloud instance to host or access data related to the TikTok/WeChat claim, the deployment of publicly available tools to facilitate distributed denial‑of‑service attacks, and the encouragement of civilian participation in those DDoS efforts. The group has also leaked data via hacking forums, posted screenshots purporting to show unauthorized access, and made breach claims on social media platforms. No specific malware families or custom tooling are described in the provided sources.
Attribution information is limited; the group is publicly linked to the #OpRussia hacktivist movement and has been associated with the moniker AgainstTheWest across multiple incident reports. While its possible location is noted as China, no definitive state sponsorship or criminal consortium affiliation is established in the available evidence. The group’s public communications emphasize ideological alignment rather than ties to any government or organized crime syndicate.
Representative operations cited in the sources include the claimed breach of TikTok and WeChat user data and source code, the leakage of hashed passwords and internal databases belonging to Russian entities such as the GRU, Gazprom and Lukoil, and the assertion of access to Rosatom’s internal reports and testing environments. These incidents illustrate the group’s pattern of asserting compromises, sharing alleged proof on forums and social media, and aligning its activities with broader hacktivist campaigns targeting perceived adversaries.
Incidents
Attributed incidents are available to members.
9 incidents