Keymous+ is a hacktivist threat group and North African hybrid actor assessed by researchers to originate in Algeria. Public reporting describes it as blending political messaging with commercial DDoS operations, including a suspected operator-level relationship with the EliteStress DDoS-for-hire platform, though no public ownership proof is cited. The group first appeared publicly in November 2023 with a DDoS claim against Morocco’s national e-Visa portal and framed early activity as solidarity with Palestinians under the “Hack for Humanity” banner. It has also been described as active in broader geopolitical campaigns including #OpIsrael and #OpIndia, and as part of pro-Iran/pro-Palestinian and anti-India hacktivist ecosystems. Keymous+ is described as having an internal Alpha Team for breaches and leaks and a Beta Team for DDoS operations, with the Beta Team responsible for virtually all confirmed operations and the Alpha Team largely inactive by mid-2025. A 2026 interview cited in the content states that Keymous+ controls sub-groups including Anonymous Algeria, DDOS54, and Hack for Humanity. The group maintains Telegram channels including KMPteam, Keymous_V2, keymous_team, and keymous, operates KeymousPlusBot, and is active on X as KeymousTeam. Its activity is centered on distributed denial-of-service attacks using publicly available booter/stressor services and DDoS-for-hire infrastructure. Reported attack methods include amplification and flooding techniques such as CLDAP, DNS, NTP, memcached, SNMP, NetBIOS, rpcbind, L2TP, WS-DD, chargen, TCP SYN floods, UDP floods, DNS query floods, and Layer-7 HTTP/2 floods. The group reportedly posts check-host.net verification links on Telegram as proof of downtime and for promotion. NETSCOUT telemetry confirmed 249 DDoS attacks attributed to Keymous+ between February and September 2024, while public claims exceeded 700 attacks by 2025, indicating inflated self-reporting mixed with genuine operations. Confirmed targeting spans 15 countries and 21 industry sectors, with government organizations the largest victim category, followed by telecommunications, financial services, transportation and logistics, hospitality, healthcare, education, and energy. Morocco, Saudi Arabia, Sudan, India, and France are identified as the most targeted countries. The content also places Keymous+ in campaigns against European financial institutions and in anti-India activity targeting Indian government and financial sectors. Keymous+ is repeatedly described as highly collaborative. Reported alliances and coordination include NoName057(16), Mr Hamza, AnonSec, Moroccan Dragons, Inteid, Anonymous Kashmir, and other hacktivist entities operating via Telegram. The content specifically notes announced collaboration between Keymous+ and Inteid, and places Keymous+ among the most active groups during Middle East escalation periods, including a window in which Keymous+, DieNet, and NoName057(16) accounted for most recorded hacktivist DDoS claims globally.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-volume hacktivist actor active in Middle East crisis mobilization, contributing attack claims, rhetoric, target lists, and coalition signaling.
North African hybrid hacktivist and commercial DDoS actor assessed as highly prolific in global DDoS claim activity, using a commercial DDoS-as-a-Service platform, alliance operations, and politically themed campaigns targeting government and other public-facing infrastructure.
Conducting DDoS campaigns against European financial institutions, with activity peaking around elections and heightened political tension.
Hacktivist group conducting structured, publicly tracked campaigns against Gulf government targets with daily target declarations and uptime verification.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.