Criminal service / underground operation

DDoS54

DDOS54 (often written “DDoS54”) is an openly self‑promoting hacktivist brand primarily associated with disruptive Distributed Denial‑of‑Service (DDoS) activity. Public reporting in 2025 described the group as Algerian and linked its operations to periods of heightened Algeria–Morocco political tension, with multiple Moroccan government portals reportedly impacted during April 2025.

Unlike financially motivated intrusion sets, DDOS54’s operational posture is best modeled as “visibility‑seeking disruption”: high‑volume traffic floods aimed at availability loss, reputational pressure, and narrative effect. The group’s observable footprint is therefore concentrated in target‑availability incidents (service downtime), public claims, and opportunistic collaboration with other DDoS‑centric collectives.

A key open‑source signal is an announced partnership with the North‑African DDoS collective Keymous+ in April 2025, followed by reporting of increased DDoS traffic volume and more complex attack vectors (including amplification) in the same timeframe.

Confidence: Medium. Core assessments are anchored to public claims/reporting about specific outages and third‑party observations of DDoS vector evolution; attribution to a cohesive “organization” (vs. a brand used by a loose cadre) remains uncertain.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-19