Keymous+
Aliases: keymous, Keymous Plus
- First seen
- 2022-06-01 00:00:00
- Primary motivation
- ideology
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- hacktivist
- Profile updated
- 2026-07-07 12:26:00
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:bh country_code:il
Context
Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructure. The group has claimed access to sensitive data, including over 300,000 records from Israel's Ministry of Education, and has engaged in reconnaissance activities against various ministries in Bahrain and other nations. Keymous employs diverse infrastructure, including compromised IoT devices and DDoS-for-hire platforms, to amplify attack bandwidth. Their operations have been characterized by a focus on politically motivated cyberattacks, particularly in the context of regional conflicts.
Reports & references
- socradar.io — Telegram Activity Timeline Iran Israel Us War (report)
- netscout.com — Keymous Threat Actor Profile (report)
- cyfirma.com — Firewalls And Frontlines The India Pakistan Cyber Battlefield Crisis (report)