The Jester (hacktivist)
The Jester is an unidentified computer vigilante who describes himself as a grey hat hacktivist. He claims to be responsible for attacks on WikiLeaks, 4chan, Iranian President Mahmoud Ahmadinejad, and Islamist websites. He claims to be acting out of American patriotism. The Jester uses a denial-of-service tool known as "XerXeS", that he claims to have developed.
History
Identity and communication
The Jester first appeared on Twitter, where he announced his attack on the Taliban website alemarah.info on January 1, 2010. On June 26, 2010, he established his WordPress blog "Jester's Court". The Jester also communicates via his I2P IRC channel #jester and cautions these are the only three authentic methods of communication from him: "As per usual, because of the large amount of imposters trying to pass themselves off as me I will only speak in THREE places, here via this blog, my twitter and the i2p IRC network outlined above where my nick is registered to myself. If you see a ‘jester’ anywhere else it's not me." In November of 2017 Jester set up an instance of the Mastodon social networking server, named Counter Social, where he continues to use the alias @th3j35t3r.Military service
The Jester had stated that he was a former soldier and had served in Afghanistan and elsewhere. A former defense operative claimed that The Jester was a former military contractor involved in US Special Operations Command projects. On April 10, 2012, The Jester gave a live chat interview to a class of Computer Science students at the University of Southern Maine where he confirmed his military service and stated he served four "operational tours".XerXeS and other tools
The Jester claims to have originally developed his DoS script as a means to test and harden servers. After learning from an article that Jihadists were using the Internet to recruit and coordinate terror cells, The Jester resolved to disrupt online communications between Jihadists. He weaponized his script and created a front-end known as "XerXeS" in order to solve the script's usability problems.Hacking history
On January 1, 2010, The Jester began a campaign against Jihadist websites. His first target was alemarah.info, which was the Taliban's website at the time.The Jester posted several tweets claiming to be responsible for the downtime WikiLeaks was experiencing. He justified his alleged attacks by claiming that WikiLeaks was "attempting to endanger the lives of our troops, 'other assets' & foreign relations." In retaliation to The Jester's reported efforts, hacktivists including a group named Anonymous in support of WikiLeaks were reported as temporarily disrupting the website of MasterCard as well as attacking websites of Amazon and PayPal.
On November 29, 2010, someone claiming to be The Jester stated that he had been raided by the U.S. and attempted to solicit money for legal fees. The Jester purported that the person was an impostor, though writers at InfoSecIsland believe the hoax was created by The Jester himself.
On December 28, 2010, a DoS attack targeted 4chan.org. On that same day, The Jester tweeted "4chan.org — that looks like a TANGO DOWN maybe you guys pissed off the wrong person trying to ID me?" This tweet is believed to be a reference to claims by 4chan users that The Jester was a man from Montana.
On February 21, 2011, The Jester began a DoS attack on several sites belonging to the Westboro Baptist Church for celebrating the death of homosexual U.S. servicemen.
In March 2011, The Jester employed a different style of attack by using an XSS vulnerability to make it appear as if fabricated articles were inserted online Libyan newspapers The Malta Independent Online and the Tripoli Post. On March 28, 2011, he tweeted links to the forged articles. The articles were not visible in search, or to viewers of those websites and viewable only via the inserted links. These tweets drew the attention of Anthony M. Freed, who examined the articles and discovered they were anomalies not contained in the newspapers' respective archives. Further inspection by Freed revealed The Jester left a watermark of his signature Harlequin avatar on the articles he created, which can only be seen by tilting the computer monitor back at an angle. The fabricated articles reported degradation in troop morale among fighters loyal to Muammar Gaddafi and incidents of his soldiers abandoning their posts. Freed concluded The Jester's objective was a "psyops campaign aimed at breaking the spirit of the troops loyal to Libyan strongman Muammar Gaddafi." The Jester confirmed this in a subsequent interview later the same year.
In June 2011 The Jester vowed to find and expose members of LulzSec. He attempted to obtain and publish personally identifiable information of key members within group, whom he described as "childish". On June 24, 2011, he claimed to have revealed the identity of LulzSec leader Sabu as Xavier Kaotico, an information technology consultant possibly from New York City. In July of the same year he falsely accused Hugo Carvalho, a Portuguese IT professional, of also being Sabu, leaving The Jester's outing claims to be considered suspect. However, in a post on his blog in November 2011, The Jester retracted his prior identifications for "Sabu", issued an apology and correctly identified "Sabu" as Hector Xavier Monsegur, 28, of New York. Sabu's identity was confirmed on March 6, 2012, when Monsegur was arrested by the FBI and it was revealed that he had been acting as an FBI informant in the interim.
In October 2011, at the Hackers Halted USA conference, The Jester gave a surprise live presentation and fielded questions through an online chat with presenter Jeff Bardin. His identity was authenticated via his Twitter account. Jester answered questions about XerXeS and other tools in development and discussed his motivations for attacking militant jihadi recruiting websites. On August 26, 2012, Bardin hosted a similar presentation at Utica College for the college's Cybersecurity Master's program.
Late November 2011, th3j35t3r claimed to take down multiple jihadist sites permanently, with his newest tool known as 'Saladin'. Saladin is claimed to be similar to other 'Apache Killer' tools used by hackers. Critics have claimed Saladin does not exist, and that he is relying on domain expiration.
On May 14, 2012, The Jester's Twitter account appeared to have been deleted, along with all posts on his WordPress blog. However, the Twitter account and WordPress blog were merely temporarily deactivated and were subsequently restored May 16, 2012.
On July 2, 2013, the Jester took responsibility for a series of DoS cyberattacks against the Ecuadorean stock exchange and the country's tourism website, and promised to attack any other governments considering granting asylum to NSA leaker Edward Snowden. In a June blog post, he wrote that Snowden "is not a goddam hero, here to save Americans from 'the government' because of privacy infringements and breaches of the 4th amendment, he is a traitor and has jeopardized all our lives." In tweets, the Jester also alluded to a plan to seize control of the fire alarms at the Ecuadorean embassy in London, which would force WikiLeaks founder Julian Assange to set foot on UK soil and face potential extradition to Sweden to face sexual assault charges.
On October 21, 2016, the Jester took responsibility for "defacing" the official website of the Russian Ministry of Foreign Affairs. The "hack" was later shown to be fake, actually being a POST based XSS on the website, not a deface or hack.