Hacktivist & leaktivist catalog: Anonymous, LulzSec, WikiLeaks, LAPSUS$, and the state-aligned DDoS crews
Batch 3 of the threat-actor catalog - ideologically- or notoriety-motivated actors, distinct from paid state espionage and organized ransomware (though the lines blur).
Classic hacktivism
- Cult of the Dead Cow (1984-) coined "hacktivism", shipped Back Orifice, spun up Hacktivismo - the ideological ancestor.
- Anonymous (~2008-) - leaderless DDoS/doxxing/defacement: Project Chanology, Operation Payback (Visa/Mastercard/PayPal, 2010), HBGary Federal, #OpISIS, #OpRussia (2022). A banner anyone can fly, not an org.
- LulzSec (2011) - a high-profile Anonymous splinter (Sony, PBS, CIA.gov); collapsed after leader "Sabu" became an FBI informant - the template for infiltrating leaderless crews.
Leaktivism
- WikiLeaks (2006-) - Collateral Murder, the Iraq/Afghan War Logs, Cablegate (2010, Manning-sourced); Vault 7 (2017), the CIA cyber-tools dump (source Josh Schulte, convicted 2022) - the CIA's analog to the NSA's Shadow Brokers loss.
- Contested: the US IC assessed that GRU/APT28-hacked 2016 DNC/Podesta emails were routed to the public via WikiLeaks; WikiLeaks denied a Russian source. Both framings noted.
- Guacamaya (2022) - Latin American hacktivists behind mega-leaks of military/police archives (Mexico's SEDENA, plus Chile/Peru/Colombia) - leaktivism in the Global South.
Notoriety / extortion
- LAPSUS$ & "The Com" - teen crews (UK/Brazil) that breached Microsoft, NVIDIA, Okta, Samsung, Uber via help-desk vishing, SIM-swaps, MFA-fatigue - simple TTPs, big targets (US CSRB studied them). The Com is also where Scattered Spider came from - wiring to the eCrime block.
State-aligned DDoS (the Russia-Ukraine war wave)
- Killnet, NoName057(16) (the crowdsourced "DDoSia" project; EU's Operation Eastwood, 2025), and Anonymous Sudan (branded Sudanese but linked to Russia/Killnet; DDoS'd Microsoft 365/OpenAI/X in 2023 - though DOJ indicted two Sudanese brothers in 2024, complicating the theory) - pro-Russia.
- IT Army of Ukraine - a government-endorsed volunteer collective attacking Russian targets - openly blurring the civilian/combatant line in cyberwar.
Honest limits
"Anonymous" is a banner, so operations "by Anonymous" are self-claims. Attribution of leak-org intent (transparency vs foreign conduit) and of state-aligned crews' true sponsors is contested - presented from both sides. Named individuals (informants, defendants) exist in the public record but are referenced in notes, not modeled as nodes.
Sources: DOJ indictments (LulzSec/Sabu; Anonymous Sudan 2024; Vault 7/Schulte); US IC 2016-election assessment; Europol Operation Eastwood (2025); US CSRB (LAPSUS$ 2023); press. Cross-refs: Russia, Ukraine, US_Government, FBI, DOJ, Scattered_Spider/The_Com, APT28, Malware_Lineage.
← Research index · structured data: spec-hacktivist-catalog.json · spec-hacktivist-catalog.md