Modern hacktivism is no longer the domain of isolated collectives operating independently. Keymous+, the North African DDoS-focused threat actor, has positioned itself as a central node in a growing federation of hacktivist groups, forming documented alliances with entities spanning Russia, Pakistan, Indonesia, and Western Europe. These alliances — formalized through Telegram announcements, co-branded operations, and shared infrastructure — constitute what analysts at Orange Cyberdefense describe as a "loosely connected federation of cyber insurgents" operating with network effects that dramatically amplify any single member's operational reach. Understanding this network is essential to anticipating the scope and trajectory of Keymous+-associated threats.
Key Alliance Partners
Keymous+'s alliance portfolio, documented through open-source intelligence from Orange Cyberdefense and Radware, includes the following confirmed or assessed partners:
- NoName057(16) — The Russia-affiliated pro-Kremlin hacktivist group and Keymous+'s most prominent allied partner. The two groups have collaborated on operations including the Red Eye Op campaign, sharing attack infrastructure and cross-promoting each other's claims. NoName057(16) operates the DDoSia platform, functionally analogous to Keymous+'s EliteStress association.
- Mr Hamza — A prolific hacktivist operator that regularly co-brands operations with Keymous+ and has been observed sharing Telegram infrastructure for coordinated campaign announcements.
- Moroccan Dragons — A North Africa-based group providing regional intelligence sharing and operational cover for Keymous+ activities across the Morocco-Algeria corridor, despite the historical Algerian-Moroccan cyber rivalry that partly motivated Keymous+'s founding.
- Rabbit Cyber Team and Hunter Killerz — Documented participants in Keymous+-coordinated operations, primarily providing amplification of attack claims and supplementary DDoS capacity.
- CYBER TEAM INDONESIA — Keymous+ formally announced an alliance with this group in October 2024, expanding its operational reach into Southeast Asia.
- Pakistan-based cells within the Holy League — Orange Cyberdefense identifies a Pakistan-aligned cell as an integrated partner focused on leak amplification and defacement operations, with motivations fusing Islamist ideology with explicit anti-Zionist posturing.
- Inteid — Documented collaboration in June 2025, with both groups explicitly supporting Iranian cyberwar efforts and naming specific Israeli media targets following the Israel-Iran escalation.
The Holy League Framework
The Holy League is a loosely structured alliance framework within which Keymous+ operates as a significant participant. The coalition includes groups with diverse and sometimes contradictory motivations — pro-Palestinian, pro-Iranian, Islamist, Russian nationalist, and pure cybercriminal actors — unified primarily by shared infrastructure, a common list of adversaries, and the operational benefits of collective visibility. The Holy League does not appear to have a centralized command structure; rather, it functions as a reputational and logistical network in which member groups share attack tooling, amplify each other's Telegram posts, and occasionally coordinate simultaneous campaigns against shared targets. This decentralized model makes the alliance resilient to disruption — the takedown or deplatforming of any single member has limited impact on the broader network's operational capacity.
Red Eye Op and Co-Branded Campaign Architecture
The Red Eye Op represents the most documented example of Keymous+'s co-branded campaign model. Executed in coordination with NoName057(16), Moroccan Dragons, Rabbit Cyber Team, and others, the operation targeted multiple countries simultaneously, with each allied group contributing DDoS capacity directed at pre-agreed target lists. The co-branding serves multiple strategic purposes: it inflates the apparent scale of any given operation, allows participant groups to claim credit for collectively generated disruption, and reinforces the reputational standing of all involved parties within the hacktivist community. This "influencer economy" model — where follower counts, attack claim frequency, and alliance affiliation function as proxies for credibility — has become a defining structural feature of contemporary hacktivism.
Implications for Threat Intelligence and Attribution
The federated nature of Keymous+'s alliance network creates significant attribution complexity. When a DDoS attack is claimed under a shared operation banner, determining which specific group's infrastructure generated the traffic — and whether commercial DaaS platforms like EliteStress or NoName057(16)'s DDoSia were used — requires network-level telemetry that is rarely available to external analysts. Additionally, the presence of both pro-Russian (NoName057(16)) and pro-Iranian (Inteid, Holy League cells) allies within the same network raises questions about whether Keymous+ is being instrumentalized by state actors, or whether the alliances are genuinely opportunistic and ideologically eclectic. IntelFusions assesses with low confidence that Keymous+ receives direct state direction from any government, and with moderate confidence that the group opportunistically aligns with state-adjacent actors when doing so amplifies operational visibility and revenue.
Intelligence Assessment
The Keymous+ alliance network represents a force multiplier that transforms a regionally significant actor into a globally relevant threat. Security teams should monitor the full ecosystem of Keymous+-affiliated groups — not only the group's own channels — for early indicators of coordinated campaign planning. Historical patterns suggest that major geopolitical events (military strikes, diplomatic ruptures, contested elections) reliably trigger coordinated multi-group campaigns within 24–72 hours. During such periods, organizations in government, finance, telecommunications, and energy sectors across Europe, the Middle East, and Asia should treat elevated DDoS risk as a baseline operational assumption rather than an exceptional scenario.
This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. Claims described herein have not been independently verified unless explicitly stated.