Executive Summary
Between late April and early May 2026, iQBlack observed activity attributed to Q22, an emerging threat linked to the pro-Russian hacktivist environment. The material analyzed shows a short sequence of publications in which the actor claims responsibility for alleged disruptions affecting resources associated with Morocco, Israel, and Jordan.
The observed activity does not currently allow confirmation of effective operational impact or technical compromise of the mentioned resources. In several cases, the publications rely on screenshots and external availability reports, such as check-host, a type of evidence that may reflect partial unavailability, mitigation, filtering, temporary failures, or simply the propagandistic use of weak signals.
Even with these limitations, Q22 is relevant as an early signal. Its appearance takes place within a particularly active pro-Russian ecosystem, where micro-actors can gain visibility through public claims, opportunistic target selection, and declared links with smaller groups. The relevance of the case lies in the early identification of an operational identity that merits continued monitoring.
Key Judgments
- Q22 should be treated as an emerging threat under evaluation, not as a consolidated actor.
- The observed publications attribute to the actor alleged disruptions affecting resources linked to Morocco, Israel, and Jordan, but the impact could not be independently confirmed.
- The mentioned domains include rnesm.justice.gov.ma, tanwer.ma, and 9000000.co.il, along with a later claim involving access to data related to Mutah University.
- The target selection appears, for now, more dispersed than doctrinal, suggesting a possible logic of opportunity or operational “probing.”
What Happened
Q22 appears associated with a short series of publications in which it attributes to itself alleged actions against resources of different types. The first set of signals is concentrated on Morocco, with mentions of rnesm.justice.gov.ma, linked to an institutional registry resource, and tanwer.ma, a Moroccan information site. Later references were also observed to the national portal of the Kingdom of Morocco and to availability reports associated with resources from the country.
The activity also includes a publication related to 9000000.co.il, a domain linked to an Israeli digital insurance platform. In this case, as with the previous ones, the available material does not allow confirmation of an effective disruption or determination of whether a real window of impact existed.
On 6 May, Q22 published a reference to Jordan and later claimed an alleged breach of the Mutah University database, stating access to 12,000 academic documents and university-related data. This claim represents a shift in tone compared with the availability-focused publications, as it introduces a data-access narrative. Without additional external evidence, it should be treated as an unconfirmed claim.
Operational Assessment
Q22’s activity does not appear to be focused on a single type of operation. The set combines alleged availability disruptions, the signaling of institutional or private domains, and a claim of access to academic data. This combination suggests an early stage of operational definition, rather than a homogeneous campaign with clearly consistent objectives, methods, and outcomes.
The use of external availability reports as visual support reduces the evidentiary weight of the publications. This type of resource can be useful to show a punctual anomaly, but it is not sufficient by itself to confirm intrusion, effective denial of service, or control over infrastructure. In practical terms, Q22 claims responsibility for actions; the effectiveness of those actions remains pending corroboration.
The selection of Morocco, Israel, and Jordan does not yet present a sufficiently clear geopolitical logic. Within the pro-Russian ecosystem, broad narrative justifications may exist for targeting Western objectives or countries perceived as aligned with Ukraine. However, the resources mentioned by Q22 do not currently form an evident strategic line. That dispersion supports an early hypothesis of opportunism.
Intelligence Significance
Q22 is relevant because it appears at a moment of high activity within pro-Russian hacktivism, but without being publicly integrated into the most recognizable circuits of that ecosystem. There is insufficient evidence to organically link it to more established groups or to infer subordination, sustained coordination, or membership in a larger structure.
The declared alliance with ZxS3C should be interpreted with the same caution. The link is useful as a relational signal, but it does not confirm technical cooperation, shared infrastructure, or joint planning. In emerging actors, this type of association may respond both to operational needs and to reputational construction.
Q22’s visual identity also provides a contextual signal that is at least noteworthy. The use of an anthropomorphized animal avatar, with an offensive gesture, Russian flag, and confrontational aesthetic, fits a visual pattern similar to the one used by NoName057(16). Despite this compositional similarity, it would not currently be prudent to infer derivation, separation, or organizational continuity.

Analytical Closing
Q22 should be read as an early signal within a pro-Russian hacktivist environment. The available evidence does not allow confirmation of advanced capability or sustained impact, but it does justify keeping the actor under monitoring. Its initial relevance lies in the combination of dispersed targeting, hostile narrative, declared links with another smaller actor, and the use of public indicators to build an operational presence still under evaluation.
Explore 3C-INT
Expand actor, campaign and operational-link tracking through a structured intelligence layer.
Get new publications
Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.