APT / THREAT GROUP

Sath-ı Müdafaa

🇹🇷Turkey-attributed
1
campaigns
1
aliases
Last seen:Mar 17, 2026

Intelligence Profile

A Turkish hacking group, Sath-ı Müdafaa, is encouraging individuals to join its DDoS-for-Points platform that features points and prizes for carrying out distributed denial-of-service (DDoS) attacks against a list of predetermined targets. Their DDoS tool also contains a backdoor to hack the hackers. So the overarching motivation and allegiance of the group is not entirely clear.

Intelligence Assessment

Sath-ı Müdafaa is a Turkish threat group that encourages individuals to participate in its DDoS-for-Points platform, which offers rewards for carrying out distributed denial-of-service (DDoS) attacks against predetermined targets. The group's DDoS tool also contains a backdoor, making its overarching motivation and allegiance unclear.

Outlook

Sath-ı Müdafaa was last active on 2026-03-18, indicating current activity. The group's use of a DDoS-for-Points platform and the presence of a backdoor in its tool suggest a complex and potentially deceptive threat.

Generated by the CTIWATCH analysis pipeline from this actor's tracked data (victims, campaigns, TTPs, activity). Attribution and assessments may be incomplete — verify against primary reporting before acting.

Threat Analysis

Sath-ı Müdafaa is a known-sophistication threat actor attributed to Turkey, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

Sath-ı Müdafaa — Active Operations March 2026

Sath-ı Müdafaa is a unknown-motivation threat actor attributed to TR. A Turkish hacking group, Sath-ı Müdafaa, is encouraging individuals to join its DDoS-for-Points platform that features points and prizes for carrying out distributed denial-of-service (DDoS) attacks against a list of predetermined targets. Their DDoS tool also contains a backdoor...

MEDIUM2026

Quick Facts

TypeAPT / Threat Group
Origin🇹🇷 Turkey
Aliases1
SourceMalpedia

Also Known As

Sath-ı Müdafaa

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.