Keymous+: Profile of a North African Hacktivist Collective Claiming 700+ DDoS Attacks in 2025

Since its emergence in November 2023, the hacktivist collective Keymous+ has grown from an obscure North African threat actor into one of the most operationally prolific DDoS-focused groups in the current global hacktivist landscape. Claiming responsibility for over 700 DDoS attacks in 2025 alone, the group has disrupted government portals, telecommunications infrastructure, financial platforms, educational institutions, and manufacturing sites across Europe, North Africa, the Middle East, and Asia. A comprehensive analysis by Radware established Keymous+ as one of the top two most active hacktivist DDoS operators globally in 2025, alongside the Russian-affiliated collective NoName057(16).

Origins and Identity

Keymous+ traces its roots to Algeria in late 2023, originating as a small collective of disaffected coders. According to Orange Cyberdefense's intelligence bureau, the group's emergence was catalyzed by two converging pressures: the longstanding cyber rivalry between Algeria and Morocco, and the broader hacktivist mobilization triggered by the October 2023 Gaza crisis. The group publicly identifies itself as "North African hackers" and operates Telegram channels and an X account under the handle @KeymousTeam as its primary communications infrastructure. Despite this self-identification, Keymous+'s targeting patterns are notably inconsistent with any single ideological or geopolitical agenda. Victims span Israeli manufacturing sites, French telecommunications providers, Indian financial platforms, Danish universities, and Gulf government portals — a geographic and sectoral range that defies traditional hacktivist categorization.

Operational Structure

Keymous+ has publicly claimed a bifurcated internal structure. The Alpha Team, responsible for data breaches and leak operations, has been reported as largely inactive since mid-2025. The Beta Team, focused exclusively on DDoS campaigns, remains highly active and constitutes the operational core of the group's current activities. This division of labor suggests a degree of internal organization beyond the typical ad-hoc hacktivist cell, though independent verification of this structure from non-open sources remains limited. The group's operational methodology relies on commercially available DDoS-for-hire infrastructure, primarily EliteStress, supplemented by shared botnets and coordination with allied groups. Targets are announced via Telegram and X, with availability verification provided through Check-Host.net links — a practice that serves both as operational proof and as reputation-building within the hacktivist ecosystem.

Targeting Patterns and Sectoral Focus

An analysis of Keymous+ targeting data compiled by Radware identifies government entities as the primary target sector, comprising 27.6% of all claimed attacks. The top three most heavily targeted countries in 2025 were India (10.7%), France (10.3%), and Morocco (8.61%) — a distribution that reflects both opportunistic campaign participation and regionally motivated operations. The group has participated in operations under flags including #OpIndia, #OpIsrael, #OpFrance, and most recently #Op_Epstein_Gulf, though analysts caution that these ideological banners frequently serve as post-hoc justifications for attacks driven more by visibility and momentum than principled targeting logic. Check Point's 2025 Financial Threat Landscape Report noted Keymous+ as responsible for 121 attacks against financial sector entities alone, making it the most active single threat actor in that vertical for the year.

Commercialization and the Hacktivism-Crime Nexus

A significant intelligence concern regarding Keymous+ is the apparent convergence of hacktivist branding with commercial cybercrime operations. The group has publicly promoted and is assessed with moderate confidence to operate or hold insider access to EliteStress, a subscription DDoS service offering attack capabilities ranging from €5 per day to €600 per month. Available attack vectors include DNS amplification, UDP floods, and HTTP/2 strikes, delivered via Telegram bots. A post by a Keymous+ representative explicitly inviting followers to "join us" on EliteStress was noted by Radware analysts as indicative of operational overlap rather than simple affiliation. This commercialization trajectory has led some analysts to question whether Keymous+ is a genuine hacktivist collective or a threat actor using ideological framing as a reputational cover for revenue-generating cybercrime services — a pattern increasingly common in the modern hacktivist ecosystem.

Intelligence Assessment

IntelFusions assesses with moderate-to-high confidence that Keymous+ will continue to conduct high-volume DDoS campaigns through 2026, with operational tempo closely correlated to geopolitical escalation events — particularly those involving Iran, Israel, France, India, and Morocco. The group's low technical barrier to entry (relying on DaaS platforms) combined with its sophisticated reputational strategy and alliance network makes it a persistent nuisance-tier threat to internet-facing government and financial infrastructure. Organizations in target regions should treat Keymous+ as a sustained ambient threat rather than an intermittent actor, maintaining always-on DDoS mitigation postures accordingly.

This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. Claims described herein have not been independently verified unless explicitly stated.

Read the full analysis on IntelFusions