Two Sudanese Nationals Charged as Anonymous Sudan DDoS Empire Dismantled After 35,000 Attacks

U.S. authorities have unsealed charges against two Sudanese nationals behind Anonymous Sudan, one of the most prolific DDoS-for-hire operations in recent history, Europol announced on October 16, 2024, following an international investigation spanning multiple countries.

35,000 Attacks, $10 Million in Damages

Anonymous Sudan's custom DDoS tool was used to launch over 35,000 attacks in approximately one year, causing more than $10 million in damages to U.S. victims alone. The group's target list reads like a who's-who of Western government and critical infrastructure: the U.S. Department of Justice, Department of Defense, FBI, State Department, and major technology platforms and network service providers.

European victims included governments and organizations across the continent, with intelligence contributions from authorities in Sweden, Luxembourg, and France, alongside the European Union Agency for Cybersecurity (ENISA) and the European Investment Bank.

Infrastructure Seized

In March 2024, the FBI obtained seizure warrants to disable Anonymous Sudan's attack infrastructure. The seizures targeted computer servers used to launch and control DDoS attacks, servers that relayed commands to broader attack networks, and accounts containing the source code for the group's DDoS tools — which had also been sold as a service to other criminal actors.

Europol noted that the group conducted "destructive DDoS attacks to support their ideologically-motivated agenda," blending hacktivism with cybercrime-as-a-service.

International Coordination

Europol coordinated the European dimension of the investigation, facilitating cooperation between national authorities and organizing cross-border intelligence sharing. The agency provided analytical support that synthesized intelligence from multiple sources to map out the criminal network and its infrastructure. The charges represent a significant milestone in the ongoing effort to dismantle ideologically motivated DDoS operations that straddle the line between hacktivism and organized cybercrime.

Read the full analysis on IntelFusions