Keymous+
Keymous+ is a hacktivist threat group and North African hybrid actor assessed by researchers to originate in Algeria. Public reporting describes it as blending political messaging with commercial DDoS activity, including a suspected operator-level relationship with the EliteStress DDoS-for-hire platform, although no public ownership proof is cited. The group first appeared publicly in November 2023 and framed early activity around pro-Palestinian messaging under a “Hack for Humanity” banner, later participating in campaigns such as #OpIsrael and #OpIndia. Keymous+ is primarily associated with distributed denial-of-service operations. Researchers describe an internal structure with an Alpha Team for breaches and leaks and a Beta Team for DDoS operations, with Beta Team driving virtually all confirmed activity and Alpha Team appearing largely inactive by mid-2025. The group uses publicly available DDoS booter services and has been described as a marketing persona for EliteStress. Observed attack methods include amplification and flooding techniques such as CLDAP, DNS, NTP, memcached, SNMP, NetBIOS, rpcbind, L2TP, WS-DD, chargen, TCP SYN floods, UDP floods, DNS query floods, and Layer-7 HTTP/2 floods. It publicly posts uptime verification links, including check-host.net, and researchers reported attack clustering around 06:00 UTC. Confirmed targeting spans government, telecommunications, financial services, transportation and logistics, hospitality, healthcare, education, and energy. Government entities are the largest confirmed victim category. NETSCOUT telemetry cited Morocco, Saudi Arabia, Sudan, India, and France as the most targeted countries. Reporting also places the group in DDoS activity against European financial institutions, Indian government and financial sectors, and Middle Eastern targets including Egypt. Between February and September 2024, NETSCOUT independently verified 249 DDoS attacks attributed to Keymous+ across 15 countries and 21 industry sectors, while the group later claimed more than 700 attacks in 2025; researchers assess those public claims are inflated. Keymous+ is repeatedly described as highly collaborative within the hacktivist ecosystem. Reported alliances and coordinated activity include NoName057(16), DieNet, DarkStorm Team, Mr Hamza, AnonSec, Inteid, Anonymous Kashmir, Moroccan Dragons, and DDoS54. Content also states that Keymous+ announced collaboration with Inteid in support of Iranian cyberwar efforts, and that it publicly announced alliances and resource sharing through Telegram. A 2026 interview cited in the content stated that Keymous+ controls sub-groups including Anonymous Algeria, DDOS54, and Hack for Humanity. The group maintains a Telegram-centric presence, including channels such as KMPteam, Keymous_V2, keymous_team, and keymous, and operates KeymousPlusBot. It is also active on X under the handle KeymousTeam. Overall, the content consistently characterizes Keymous+ as a prolific, coalition-oriented DDoS-focused hacktivist actor with North African roots and a strong overlap between ideological branding and commercial DDoS service promotion.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇮🇳 India
Where they're from
Attributed origin per open-source reporting.
- PK
Tradecraft
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North African hybrid hacktivist and commercial DDoS actor assessed as highly prolific in global DDoS claim activity, using a commercial DDoS-as-a-Service platform, alliance operations, and politically themed campaigns targeting government and other public-facing infrastructure.
Conducting DDoS campaigns against European financial institutions, with activity peaking around elections and heightened political tension.
Hacktivist group conducting structured, publicly tracked campaigns against Gulf government targets with daily target declarations and uptime verification.
Hacktivist group involved in retaliatory cyberattacks (primarily DDoS and disruption) amid heightened geopolitical tensions.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.