Jabaroot, the hacker who has dealt the biggest blow to Rabat’s intelligence after the Ceuta crisis: "He is a former Moroccan spy living in Germany"

Jabaroot, the hacker who has dealt the biggest blow to Rabat's intelligence after the Ceuta crisis: "He is a former Moroccan spy living in Germany"

This is the largest documented breach against Morocco’s security services since their founding, and possibly the biggest counterintelligence blow suffered by a North African service in Europe in recent decades: 70,381 agents exposed from two organizations: the General Directorate for Territorial Surveillance (DGST or internal intelligence) and the General Directorate of National Security (DGSN, or police).

Read more Torres distances himself from Robles and supports Marlaska: “There was no communication about the arrival of tens of thousands of people”

Among the revealed documents is something even more explosive: excerpts from the mission orders of agents who traveled to Ceuta before and during the assault on July 30. These orders, which Jabaroot threatens to publish in full, represent proof that Moroccan state agents moved to the border city to coordinate the mass entry. The leak points to Abdellatif Hammouchi (decorated by Minister Marlaska with the Grand Cross of the Order of Merit of the Civil Guard) as the top person responsible for the operation, alongside Fouad Ali el Himma, the main advisor to King Mohammed VI, but promises new documents in future releases.

Who is behind this revelation? We only have the name of a supposed group of hackers who have acted before with some success in Morocco: Jabaroot, whose meaning in Arabic is “powerful.” Although Morocco blames Algeria, its great regional rival, European intelligence services rule out that origin, despite Jabaroot itself claiming to be part of a group of “Algerian patriots.” Jabaroot debuted by stealing data from Morocco’s National Social Security Fund and about the royal palace staff and its properties.

For European intelligence services, behind the hacker group Jabaroot there is actually a single person, a kind of “lone wolf” who knows the inner workings of Moroccan security services perfectly but operates far from Morocco. Several cybersecurity companies have tracked their steps and reached some conclusions. The French company CybelAngel searched for variants of Jabaroot’s alias used on platforms like Telegram and found it led to another alias: 3N16M4, which the same hacker used on sites like GitHub.

GitHub is a platform where programmers store and share their code. It is like a professional portfolio for developers that organizes ethical hacking tournaments called “Capture The Flag”: cybersecurity challenges such as decoding passwords, finding vulnerabilities, and penetrating simulated systems. The user 3N16M4 participated in several tournaments, allowing investigators to see from which country they usually connected. The investigations led them to someone who “may be a computer engineer,” who identifies as “Tunisian” and “lives in Germany.” Shortly after, another competing company, Zecurion, reached the same conclusion.

The Spanish cybersecurity group Navakintelligence adds another interesting point to the profile: Jabaroot’s level of penetration “is hardly explainable without prior privileged access,” hence their hypothesis that this is a former Moroccan spy who has training in information systems, emigrated to Germany, and from there executes an operation comparable to what Edward Snowden did with NSA data (U.S. National Security Agency) in 2013.

Read more Robles exposes Marlaska by detailing the CNI alert one day before the mass entry in Ceuta

Intelligence services across Europe and part of the Maghreb are trying to verify the authenticity of the documents, which offer names of Moroccan agents who may have operated in different countries on the continent. From the CNI, which monitored some of them, to security services like those of the Netherlands or France, the investigations so far are positive: those names exist and in some cases are well-known to European intelligence. Although the volume of stolen data is several gigabytes and will take time to process, for now everything seems real, although the list may be old and outdated.

As a curiosity, one of the Excel documents leaked on Telegram shows the name of Mehdi Hijaouy, a shadowy former Moroccan agent and number two of external intelligence (DGED) and for years a direct advisor to Fouad Ali el Himma, the main advisor to King Mohammed VI and mastermind of the “Ceuta operation” according to Jabaroot. Caught in the internal war between the two main Moroccan intelligence agencies, he fled the country with state secrets, passed through France, and arrived in Spain in 2024, where he was almost extradited before disappearing.

Sources from the DGST claim he is hiding in a village on the outskirts of Madrid under CNI protection, although other versions suggest Spanish services tried to hand him over and he fled, remaining at large and wanted by the National Court. What makes his case especially explosive is that the publication Escudo Digital, specialized in intelligence, points to him as the technical architect of the Pegasus operation against Spain: the spying on Pedro Sánchez, several ministers, and journalists that the National Court shelved in January 2026 due to lack of cooperation from Israel, creator of the spyware.

Yesterday, Jabaroot itself asked on one of its Telegram channels: “Who is interested in Pegasus data related to Pedro Sánchez?”, although there is still no evidence that this hacker has access to that information.

Read more Shock in Montana after a man kills eight family members, including four children

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *