Year Established: 2023
Attribution: Global (Malaysia and Singapore-linked leadership reporting)
Motivation: Religious and political hacktivism
Modus Operandi (MO): Crowdsourced DDoS via MegaMedusa and Zeus Stresser, Telegram target lists, OT/HMI probing (SAUTER, TECO, fuel controllers), occasional leak claims
Primary Aliases: None established
RipperSec is a Telegram-first hacktivist collective that has been active since mid-2023. Public reporting has described an original Malaysian leader and, after 2024, continued operations under a decentralized structure with Singapore-linked coordination claims. They recruit volunteers, rotate commercial stresser panels, and post check-host screenshots as proof. That is a crowdsourced disruption model, not a ransomware affiliate program.
Tools repeatedly named in their 2026 waves include MegaMedusa and Zeus Stresser (TLS HTTP/2 flooder settings, including a "No CF" profile aimed at hosts they believe sit outside Cloudflare). CyberAsia has logged #OpZionistV2 against civil-society and institutional websites, and #FightChatControl / Operation Barracuda against European building-management and fuel-related interfaces. Partner banners such as The Comrade's Group appear on some target cards.
OT hits are the differentiator versus generic volunteer DDoS brands. When a SAUTER or TECO controller is exposed on the public internet, RipperSec treats it as a political trophy, not as a path to encrypt a domain controller. Do not file them as RaaS. If a leak channel appears beside a DDoS card, score the leak as a separate claim and ask for file samples before upgrading the language from claim to breach.
Defenders: hide origin IPs, enable HTTP/2 bot challenges, and pull vendor HMIs off the open internet. Put manufacturer remote access behind VPN and phishing-resistant MFA. For nonprofits and small ministries, a single cheap VPS plus one A record is the typical failure mode under MegaMedusa-style request floods.
Status: active, August 2026. Classification must remain hacktivist collective. Linked CyberAsia reports include Italian and Swedish SCADA/HMI incidents, Nature Israel downtime claims, and the Bird Foundation #OpZionistV2 card.