US disrupts Anonymous Sudan DDoS operation, indicts 2 Sudanese brothers

Share:

The United States Department of Justice unsealed an indictment today against two Sudanese brothers suspected of being the operators of Anonymous Sudan, a notorious and dangerous hacktivist group known for conducting over 35,000 DDoS attacks in a year.

Since launching in 2023, Anonymous Sudan has been behind numerous high-profile DDoS attacks, causing widespread outages and the inability for users worldwide to access targeted services. Many of their attacks were motivated by pro-Russian and pro-Palestinian causes, based on messages on the operation’s Telegram channel.

These attacks impacted well-known companies and services, including tech giants like Cloudflare, Microsoft, and OpenAI, with the threat actors capable of overloading services and making them inaccessible.

Other attacks targeted government agencies worldwide and healthcare organizations, including Cedars-Sinai Hospital in Los Angeles, where the attack disrupted systems and caused emergency services and patients to be diverted to other hospitals.

Anonymous Sudan DDoS attack on Microsoft Azure
Anonymous Sudan DDoS attack on Microsoft Azure
Source: BleepingComputer

Anonymous Sudan indicted

Today, the Department of Justice unsealed an indictment against two Sudanese nationals named Ahmed Salah Yousif Omer, 22, and Alaa Salah Yusuuf Omer, 27, for operating and controlling Anonymous Sudan.

While the group claimed to be targeting countries and organizations interfering with Sudanese politics, some researchers believed that to be a false flag and linked the group to Russia instead.

U.S. Attorney Martin Estrada told reporters in a press call that Anonymous Sudan was categorized as “the most dangerous cyber group in terms of DDoS attacks” and that the brothers were motivated by a Sudanese nationalist ideology.

Estrada said the brothers have been in custody since March when Anonymous Sudan was disrupted and infrastructure seized, but would not share what country arrested the two. However, he did state that while they are not in US custody, they have been interviewed by the FBI.

“A federal grand jury indictment unsealed today charges two Sudanese nationals with operating and controlling Anonymous Sudan, an online cybercriminal group responsible for tens of thousands of Distributed Denial of Service (DDoS) attacks against critical infrastructure, corporate networks, and government agencies in the United States and around the world,” announced the DOJ.

“In March 2024, pursuant to court-authorized seizure warrants, the U.S. Attorney’s Office and FBI seized and disabled Anonymous Sudan’s powerful DDoS tool, which the group allegedly used to perform DDoS attacks, and sold as a service to other criminal actors.”

Unlike other groups that conduct DDoS attacks, Anonymous Sudan did not compromise devices to use as part of their attacks. Instead, they utilized tools called the Skynet Botnet or DCAT that used open proxies to overwhelm targeted servers.

“I have interviewed employees at Amazon who examined data associated with Skynet Botnet attacks against Amazon customers,” FBI Special Agent Elliott Peterson explained in the criminal complaint.

“They determined that the attacks were being transmitted not from compromised victim devices, as would ordinarily be the case with a botnet, but from devices that were configured to automatically forward certain categories of Internet traffic.”

“Also called “Open Proxy Resolvers,” these “auto-forwarding” devices comprise the public part of the Skynet Botnet, and they were often the only information a Skynet Botnet attack victim would see in their network data.”

Peterson, who has been investigating Anonymous Sudan since 2023, has also been involved in other disruptions of DDoS operations as part of Operation PowerOff.

The two suspects now face charges of conspiracy to damage protected computers, and Ahmed Omer is also charged with three counts of damaging protected computers.

Ahmed Omer also faces a statutory maximum sentence of life in federal prison for reckless endangerment of life for their attack on Cedars-Sinai Hospital, which Estrada said may be the first time this statute was used in charges for a cyberattack in the US.

Lawrence Abrams

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:27 pm, Jun 26, 2025
weather icon 23°C
L: 21° | H: 24°
light rain
Humidity: 70 %
Pressure: 1010 mb
Wind: 15 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0.3 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 24°°C 0.24 mm 24% 17 mph 61 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 13 mph 61 % 1021 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
17° | 28°°C 0.2 mm 20% 10 mph 88 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 32°°C 0 mm 0% 6 mph 82 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 34°°C 0.2 mm 20% 12 mph 59 % 1019 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0.24 mm 24% 17 mph 61 % 1011 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 47 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 47 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 57 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 6 mph 61 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 8 mph 59 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 11 mph 52 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 12 mph 46 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,720.69
0.15%
Ethereum(ETH)
€2,091.35
0.89%
Tether(USDT)
€0.86
-0.02%
XRP(XRP)
€1.86
-1.05%
Solana(SOL)
€122.74
-1.61%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.137963
-2.20%
Shiba Inu(SHIB)
€0.000009
-2.00%
Pepe(PEPE)
€0.000008
-6.25%
Scroll to Top