Keymous+ Launches #Op_Epstein_Gulf: DDoS Campaign Hits Jordan, Oman, and Kuwait Government Portals

In the immediate aftermath of the February 28, 2026 U.S.-Israeli military strikes against Iran, the North African hacktivist collective Keymous+ launched a coordinated distributed denial-of-service (DDoS) campaign targeting government digital infrastructure across the Middle East, operating under the banner #Op_Epstein_Gulf. Verified takedown screenshots posted to the group's X (formerly Twitter) account, @KeymousTeam, confirm successful disruptions of the Jordan Government Portal (jordan.gov.jo), the Oman Government Portal (oman.om), and Kuwait's e-Government Portal (e.gov.kw), with availability checks conducted via Check-Host.net confirming each target was unreachable at time of claim.

Operation Context: Geopolitical Trigger

The operation name #Op_Epstein_Gulf reflects the group's framing of the U.S.-Israeli joint strike campaign a framing echoed across pro-Iran and anti-Western hacktivist channels in the days following the February 28 escalation. Within hours of the kinetic strikes, Keymous+ posted to its Telegram and X channels announcing that "online services in the Middle East will be seeing some outages," a characteristically understated but operationally accurate pre-announcement. The targeting of Jordan, Oman, and Kuwait all states that host U.S. military assets or have maintained diplomatic proximity to Western and Israeli interests is consistent with Keymous+'s established pattern of geopolitically reactive targeting. The hashtag cluster used across all posts #EliteStress #Qatar #Iran #Israel #Kuwait #Hack_For_Humanity #Op_Epstein_Gulf #Saudia #Dubai #Jordan #Bahrain #Cyber indicates a broader campaign scope beyond the three confirmed targets, with additional Gulf state infrastructure likely targeted in parallel or subsequent waves.

Confirmed Targets and Technical Evidence

Keymous+ provided Check-Host.net verification links alongside each claim, a standard operational practice for the group to establish third-party-corroborated proof of service disruption. The following government portals were confirmed as impacted:

All three claims were published within a compressed timeframe of approximately 14 hours, consistent with a coordinated, pre-planned operational tempo rather than opportunistic targeting.

Attribution and Tactical Assessment

Keymous+ publicly attributes its operations to a Beta Team responsible for DDoS campaigns. The group's Alpha Team, historically responsible for data breaches and leak operations, has been reported as inactive since mid-2025 per Radware's threat intelligence analysis. The DDoS infrastructure leveraged in this operation is assessed with moderate confidence to involve EliteStress, a commercially available DDoS-for-hire platform that Keymous+ has publicly promoted and is believed to operate or maintain privileged access to. EliteStress offers attack vectors including DNS amplification, UDP floods, and HTTP/2 strikes, delivered via a Telegram-integrated subscription model ranging from €5 per day to €600 per month. The use of Check-Host.net as a public verification mechanism is a hallmark of Keymous+ operations and serves a dual function: providing third-party evidence of disruption and amplifying perceived operational credibility to followers and peer hacktivist groups.

Broader Campaign Indicators

The hashtag infrastructure surrounding #Op_Epstein_Gulf suggests the operation is positioned as a multi-group or multi-wave campaign. Keymous+ has historically coordinated operations with entities including NoName057(16), Mr Hamza, Moroccan Dragons, Rabbit Cyber Team, and within the broader Holy League alliance framework. While co-branding with allied groups has not yet been confirmed for this specific operation at time of publication, IntelFusions assesses with low-to-moderate confidence that parallel targeting by affiliated collectives is likely given the elevated hacktivist tempo across the region following the February 28 escalation. Cybersecurity researchers at CrowdStrike have noted that Iran-aligned groups were already conducting reconnaissance and initiating DDoS attacks within hours of the strikes, a broader threat environment in which Keymous+ is positioned as a high-tempo independent actor with ideological alignment rather than confirmed state direction.

Intelligence Assessment and Recommendations

Government agencies, public administration portals, and critical digital infrastructure across Gulf Cooperation Council (GCC) states and the broader Levant region should anticipate sustained DDoS pressure from Keymous+ and affiliated hacktivist groups throughout the current geopolitical escalation cycle. Historical operational data indicates that Keymous+ is capable of sustaining multi-target, multi-day campaigns with minimal degradation in tempo. Organizations should ensure always-on DDoS scrubbing and multi-CDN failover configurations are active, as short-burst volumetric attacks sometimes dozens per day have historically overwhelmed on-demand mitigation postures. IntelFusions will monitor the @KeymousTeam Telegram and X channels for further operational announcements under #Op_Epstein_Gulf.

This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. Claims described herein have not been independently verified unless explicitly stated.

Read the full analysis on IntelFusions