CSIDB logo
Threat actor

Team Bad Dream

Attribution profile

Type
Activist
Location
United States of America
Known incidents
1 incident
Sources
1 source
First seen
2015-03-30
Last seen
2015-03-30
Updated
2026-07-30 19:25
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Team Bad Dream is a threat actor known by the aliases TrYaG Al Arab, 1337kSa and Faisal Al Hamzi, which are the handles used by its members in public statements. The group is listed as being located in the United States of America according to the available threat actor context. They have been described in reporting as Saudi hackers who operate under the collective name Team Bad Dream. Their public persona includes the use of social media contact information such as Twitter handles to facilitate communication after an operation. No further details about their internal structure, size or funding are provided in the source material.

Observed activity shows that Team Bad Dream focuses on defacing web sites belonging to government and military organizations. Their targets have included a United States Army installation website and an Egyptian government ministry site, indicating a geographic focus on North America and the Middle East. The primary objective demonstrated in these incidents is disruption through the replacement of legitimate content with a political message and an image of a national leader. The defacement messages expressed anti‑establishment rhetoric, stating that the actors do not care about external criticism. Their technical approach consists of uploading a defacement image (named ksa.jpg) to the compromised server and leaving proof of the hack via zone‑h mirrors, without any reference to malware, exploit kits or advanced persistence mechanisms.

The most cited operation is the March 30 2015 defacement of the U.S. Army Picatinny Arsenal’s Joint Munitions & Lethality Life Cycle Management Command subdomain. A second notable action occurred on March 26 2015 when the Egyptian ministry of housing utilities and urban communities website was similarly defaced and remained altered at the time of reporting. Both incidents were publicly documented with zone‑h mirrors and screenshots that confirmed the actors’ claims of responsibility. Attribution to a specific state sponsor or to a broader criminal consortium has not been established in the open source references provided. The available information therefore describes Team Bad Dream as a loosely affiliated group of individuals whose known tactics are limited to web site defacement for the purpose of conveying a political statement.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB