TheIslamic State Hacking Division (ISHD) or TheUnited Cyber Caliphate(UCC) is a merger of several hacker groups self-identifying as the digital army for theIslamic State of Iraq and Levant (ISIS/ISIL). The unified organization comprises at least four distinct groups, including theGhost Caliphate Section, Sons Caliphate Army (SCA), Caliphate Cyber Army (CCA), and the Kalashnikov E-Security Team. Other groups potentially involved with theUnited Cyber Caliphate are the Pro-ISIS Media groupRabitat Al-Ansar (League of Supporters) and theIslamic Cyber Army (ICA).[1] Evidence does not support the direct involvement of theIslamic State leadership. It suggests external and independent coordination of Pro-ISIS cyber campaigns under theUnited Cyber Caliphate(UCC) name.[2] Investigations also display alleged links to Russian Intelligence group,APT28, using the name as a guise to wage war against western nations.[3][4]
The group's actions have included online recruiting, website defacement, social media hacks,denial-of-service attacks, and doxing with 'kill lists.'[5][6][7] The group is classified as low-threat and inexperienced because their history of attacks requires a low level of sophistication and rely on publicly available hacking tools.[8][9]
Experts raised doubts about the source and nature of data from released 'kill lists' containing personal information about U.S. Military personnel claimed stolen from hacked U.S. government servers. There is no evidence that theUnited Cyber Caliphate (UCC) compromised U.S. systems. The data included public, unclassified, and often outdated information about civilians, non-U.S. citizens, and others built from old data breaches orweb scraped data.[10][11]
U.S., French, and German intelligence investigated attacks following the French Television Channel TV5Monde hack and The U.S. CENTCOM Twitter attack. All three countries linked actions by theUnited Cyber Caliphate (UCC) toAPT 28 (aka Fancy Bear), a Russian intelligence group.[3][4]
The group first emerged in hacking operations against U.S. websites in January 2015 as theCyber Caliphate Army(CCA).[1] In March 2015, the Islamic State published a "kill list" on a website that included names, ranks, and addresses of 100 U.S. military members.[12]
A pattern of similar attacks emerged after the media coverage. At least 19 individual 'kill lists,' including personal information of American, Canadian, and European citizens released between March 2015 and June 2016.[13] On April 4, 2016, all four groups united as theUnited Cyber Caliphate (UCC).[14]
In June 2016, theMiddle East Media Research Institute found and revealed to the media an alleged list of approximately 8,300 people around the world as potential lone-wolf attack targets.[15]
FrenchTV5Monde live feed hacked, social media hacked and defaced with the message "Je Suis ISIS".[18] French investigators later discounted this, instead suspecting the involvement of a hacking group,APT28, allegedly linked to the Russian government.[19]
ISIS hacks Swedish radio station and broadcasts recruitment song[20]
United States' military database hacked in early August and data pertaining to approximately 1400 personnel posted online.[21]
Top secret British government emails hacked. The emails pertained to top cabinet ministers. The intrusion was detected by GCHQ.[22]
February 28, 2016, Caliphate Cyber Army (CCA) carried out a cyber attack on the website of Solar UK, a company in the town of Battle, England. Customers were being redirected to a web page featuring the ISIS logo accompanied by a string of threats. “Fear us,” the page stated. “We are the Islamic Cyber Army”.[23][24]
On April 15, 2016 (Friday), Islamic State hackers under the name UCC successfully hacked 20 Australian websites in a coordinated attack on Australian business. Some of the websites redirected to the website containing their content.[25]
In early April 2017, UCC released a kill list of 8,786 people.[26]
In mid 2019, Islamic State affiliated hacking group hijacked 150 targeted Twitter handles using an unknown vulnerability.[27]