Hacktivist

Executive Summary

On December 6, 2024, Cyble Research & Intelligence Labs (CRIL) observed that the hacktivist alliance known as the “Holy League” on their Telegram channel declared cyberattacks against France. According to the alliance, these operations were executed in retaliation to France’s continued support of Ukraine and Israel. Prominent members of the alliance, including the pro-Russian group NoName057(16), the pro-Islamic threat actor Mr. Hamza, and the pro-Palestinian collective Anonymous Guys, amplified the announcement across their platforms. Shortly after, these groups actively participated in coordinated attacks, demonstrating a unified effort among ideologically diverse threat actors to target French assets.

The timing of the attacks coincides with a political crisis in France and the visit of U.S. President-elect Donald Trump. On December 5, the French Parliament passed a no-confidence vote against Prime Minister Michel Barnier. President Emmanuel Macron now faces mounting pressure to appoint a successor, with some calling for his resignation.

This political turmoil has created a vulnerable environment, providing hacktivist groups with an opportunity to sow chaos, disrupt public order by disrupting public and critical infrastructure, and amplify uncertainty within the nation.

Another startling development observed during the campaign is the collaboration between pro-Islamic and pro-Russian hacktivist collectives, especially when pro-Islamic groups are supporting revolutionary movements in Syria that have led to the ousting of erstwhile President Bashar-al-Assad, previously staunchly supported by Russia. This alliance highlights a pragmatic convergence of interests, where shared objectives in destabilizing common adversaries outweigh ideological differences.

“Holy League” members initiated sustained attacks on France from December 7, 2024. CRIL investigated these cyberattacks on France distinctively in two categories: coordinated attacks by the alliance members and systematic attacks individually by each group as per their modus operandi. Moreover, the “Holy League” has threatened to launch similar attacks against other countries, such as Germany.

Observations and Analysis

In a post on the Telegram channel on December 6, 2024, “Holy League” announced the campaign against France immediately after December 4, 2024, when Prime Minister Michel Barnier was ousted through a no-confidence vote. The agenda seems evident: to reap this opportunity to stir public unrest.

Figure 1 – Holy League Announces Attack on France

Between December 7 and December 10, 2024, hacktivists executed DDoS attacks, compromised Industrial Control Systems (ICS), conducted website defacements, and claimed data breaches of several French entities. This analysis will dissect each attack vector and attribute activities to specific threat groups where possible.

DDOS Attacks

Several hacktivists launched a wave of DDoS attacks on French entities from December 7 to December 10, 2024, prominent ones being NoName057(16), People’s Cyber Army, and Mr. Hamza.

Hacktivist, DDoS
Figure 2 – DDoS claims by different hacktivist groups

NoName057(16) and the People’s Cyber Army primarily focused on the official websites of French cities and other private entities, including the major French financial corporation AXA.

Mr. Hamza concentrated on high-value governmental targets, including the Ministry of Foreign Affairs, the French Directorate-General for External Security (DGSE), the French National Nuclear Energy Commission (CEA), and the French National Cybersecurity Agency (ANSSI).

Anonymous Guys directed their efforts towards several key ministries and government departments, such as the Ministry of Armed Forces, the Ministry of Agriculture and Food, and the Ministry of Solidarity and Health, among others.

According to CRIL, more than 50 separate DDoS attacks were identified against French websites over these four days, affecting multiple sectors of the economy and government. 

Hacktivist

Defacement

The pro-Russian group Z-Pentest’s defacement attacks were primarily focused on small-to-medium enterprises (SMEs) from diverse industries in France, including Energy and utilities, Agriculture and livestock, Automotive, and Hospitality. Notably, Energy and Utility firms such as Atlantic Energies Pose and Electricité Générale Lespiau and 10 other websites were defaced with pro-Russian statements.

Hacktivist, Defacement
Figure 3 – Defaced webpage of egp-peinture-decoration.fr

Unauthorized Access to CCTV and SCADA

Four Holy League members—Hunt3rKill3rs, Shadow Unit, EvilNet, and KozSec—have claimed unauthorized access to several systems in France.

Hacktivist, CCTV
Figure 4 – CCTV Access

Shadow Unit, a pro-Islamic hacktivist collective, claimed the breach of the SCADA systems of Corus Nuclear Power Plant and the French Marne Aval station.

SCADA, Critical Infrastructure, Hacktivist

Hacktivist
Figure 5 – Shadow Unit Hacktivist Group Claims Access to French SCADA Systems

KozSec, A pro-Russian collective, claimed to target an undisclosed French industry. The hacktivist group shared screenshots and videos of the intrusion, emphasizing their successful access to sensitive industrial systems.

Hacktivist
Figure 6 – ICS of Unknown French Facility Targeted by KozSec

Data Breaches

Two groups associated with the Holy LeagueShadow Unit and UserSec, claimed separately. Compromising the website plubioclimatique.paris.fr and exfiltrating over 50 PDF documents and over 100GB of data from French Government websites, respectively.

Hacktivist, Holy League, Shadow Unit

Hacktivist, Data Breach
Figure 7 – UserSec & Shadow Unit Claims about Data Breaches

Conclusion

The recent cyberattacks by the “Holy League” underscore a new, broader geopolitical landscape where hacktivist alliances can sow and exploit discord for their objectives. The collaboration between ideologically diverse groups, such as pro-Islamic and pro-Russian hacktivists, signals a shift in how adversaries may align their interests against common targets. The implications extend beyond France, as similar threats loom over other nations, signaling a new era of cyber conflict where common adversaries may overshadow ideological differences.

The post Hacktivist Alliances Target France Amidst Political Crisis appeared first on Cyble.