Keymous+

Aliases: keymous, Keymous Plus

First seen
2022-06-01 00:00:00
Primary motivation
ideology
Sophistication
intermediate
Resource level
organization
Actor type
hacktivist
Profile updated
2026-07-07 12:26:00

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:bh country_code:il

Context

Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructure. The group has claimed access to sensitive data, including over 300,000 records from Israel's Ministry of Education, and has engaged in reconnaissance activities against various ministries in Bahrain and other nations. Keymous employs diverse infrastructure, including compromised IoT devices and DDoS-for-hire platforms, to amplify attack bandwidth. Their operations have been characterized by a focus on politically motivated cyberattacks, particularly in the context of regional conflicts.

Reports & references

  • socradar.io — Telegram Activity Timeline Iran Israel Us War (report)
  • netscout.com — Keymous Threat Actor Profile (report)
  • cyfirma.com — Firewalls And Frontlines The India Pakistan Cyber Battlefield Crisis (report)

External references