{"id":422,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2022<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Unknown (North African Suspected)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Hacktivism, Financial<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Database leaks, credential theft, dark web data sales<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Keymous+, Keymous Team<\/div>\n  <\/div>\n<\/div>\n<p>Keymous (also written as Keymous+) is a threat actor group that operates at the intersection of hacktivism and financially motivated cybercrime, conducting database compromise operations and selling stolen data on dark web marketplaces and Telegram channels. The group has targeted organisations across multiple sectors in the Middle East, North Africa, and Europe, primarily exploiting web application vulnerabilities to extract and monetise sensitive data.<\/p>\n<p>Keymous has claimed the theft and sale of large databases from financial institutions, government agencies, healthcare providers, and e-commerce platforms ,  publishing sample data on hacking forums to attract buyers and establish credibility within criminal marketplaces. Their ability to extract and rapidly publish substantial data volumes suggests systematic use of automated database extraction tools following initial web application compromise.<\/p>\n<p>The group's operational model blurs the line between hacktivism and organised data theft crime: they occasionally frame operations with political or social justice messaging while simultaneously monetising stolen data through direct sales. This dual positioning allows them to attract both ideologically motivated collaborators and commercially motivated buyers within different segments of the underground ecosystem.<\/p>\n<p>Keymous represents a category of threat actor increasingly prevalent in North Africa and the broader Arab world: groups with technical capabilities sufficient to extract commercially valuable data from vulnerable web applications, who combine criminal data monetisation with opportunistic hacktivist branding to build reputation and recruit within hacking communities.<\/p>\n\n<p><strong>Operational Telemetry and Threat Vector Analysis:<\/strong> In monitored campaigns, <strong>Keymous<\/strong> executes high-volume disruptive offensives designed to maximize psychological impact and public visibility. The collective coordinates multi-vector Layer 7 distributed denial of service (DDoS) floods, automated CMS vulnerability exploitation, and database dump distributions across encrypted social channels. Enterprise security teams must deploy resilient edge web application firewalls (WAF), enforce continuous vulnerability scanning on public web assets, and establish proactive brand monitoring across dark web discussion hubs.<\/p>","link":"https:\/\/cyberasia.io\/actor\/keymous\/","name":"Keymous","slug":"keymous","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}