Unmasking Jabaroot: The New Player in the Ceuta Crisis

As the crisis in Ceuta marks its one-month anniversary, a new entity has emerged that threatens to expose the underlying causes of the influx of tens of thousands of immigrants and the precursors to the illegal assault on the autonomous city. This entity, known as **Jabaroot**, meaning 'powerful' in Arabic, has surfaced from uncertain origins and recently made headlines by leaking the identities of over 70,000 alleged Moroccan intelligence agents. Furthermore, Jabaroot threatens to disseminate sensitive information regarding espionage activities targeting several members of the Spanish government, purportedly conducted via the Pegasus software.

Jabaroot's name began circulating in Spanish media on August 24, when it published through the online platform Telegram the names of countless supposed members of Morocco's security and intelligence forces, allegedly stationed in Europe and involved in strategic Moroccan institutions. The spreadsheets reviewed by ABC reveal not only anonymous individuals but also high-ranking officials from the General Directorate of National Security (DGSN) and the General Directorate of Territorial Surveillance (DGST), including their chief, **Abdellatif Hammouchi**, frequently referred to as the 'super cop' or 'viceroy' of King Mohammed VI. Each individual is linked to a service number, identity document, bank account number, and their birth and entry dates. While the official press in Rabat has downplayed this leak, suggesting that the names may have been obtained through prior cyberattacks on organizations, doubts remain about the true intentions behind Jabaroot's actions.

Understanding Jabaroot's Objectives and Origins

But who exactly comprises Jabaroot, and what are its objectives by disseminating such sensitive information? The truth remains elusive; it is unclear whether Jabaroot is a singular individual or a collective. The name first appeared in April 2025 amidst a diplomatic spat between [Rabat and Algiers](https://www.abc.es/espana/relacion-sanchez-marruecos-planea-sobre-ceuta-20260730021450-nt.html), following the hacking of the X account of the Algerian news agency APS by pro-Moroccan hackers. Operating under the banner JabaRoot DZ — the official code for Algeria — this group presents itself as a patriotic hacktivist platform advocating for the Sahrawi cause and condemning Moroccan cyber-espionage against Algeria and several European governments. Their primary adversary appears to be Hammouchi and the corruption pervasive within Moroccan institutions.

José Miguel Rosell, co-founder and managing partner of the cybersecurity firm S2 Grupo, which monitors the activities of such entities through its cyber intelligence division LAB52, summarizes Jabaroot's modus operandi: "Seemingly, Jabaroot does not demand payment for the information; rather, it publishes it, positioning itself as an activist group." Their strategy involves a drip-feed of information, claiming control over vast amounts of data but only releasing fragments at a time. Thus far, Telegram serves as their command center, where they issue statements, conduct surveys, and share screenshots as proof of their operations. Rosell warns that such groups often leave what are known as implants in their targets, indicating they may have stolen information long ago and are merely waiting for the right moment to deploy it.

Despite the challenges in identifying the individuals behind Jabaroot, some experts suggest that the group's origins may lie within Rabat itself. "Rumors suggest that the information comes from friendly fire, likely from individuals wanting to undermine something specific without harming the rest," notes a cybersecurity expert who wishes to remain anonymous. This source indicates that while Algeria has always had capabilities in cyber warfare, Jabaroot appears to offer far more sensitive information, likely sourced from inside Morocco. They further assert that the group must have a high-ranking informant within the Moroccan intelligence community.

In light of this, it is pertinent to highlight information published by 'Le Monde' following the attack, which stated that the identity leak was the work of five former agents from Morocco's DGST. Specifically, four officers and one commissioner who defected from the service and sought asylum in Europe are reportedly demanding changes in the leadership of the kingdom's security institutions, led by the aforementioned Hammouchi. Notably, Hammouchi had recently been awarded the Grand Cross of Merit by the Minister of the Interior only months before the Ceuta crisis.

In summary, Jabaroot has been executing high-profile leaks tied to Morocco since last year, starting with the CNSS, the Moroccan social security system, where they leaked approximately 54,000 files containing banking and salary data of two million workers. Their subsequent revelations have included sensitive information regarding the royal family's financial dealings, the Tawtik notary platform, and details about the royal palace and auxiliary Moroccan forces. Now, they threaten to expose the individuals responsible for the entry of over 72,000 people into Ceuta and to reveal espionage details regarding Spanish Prime Minister Pedro Sánchez, purportedly gathered through the Israeli software Pegasus. Jabaroot has publicly questioned, "Who would be interested in the Pegasus data related to Pedro Sánchez?" While experts like Rosell express skepticism about their claims, he acknowledges that if they possess such information, they will likely release it. Their established pattern involves announcing the types of leaks they will disclose and subsequently releasing compressed information packages in PDF format.

Currently, the only confirmed details come from the Spanish government, which acknowledged that the mobile devices of Sánchez and several ministers, including Margarita Robles and Fernando Grande-Marlaska, were infected with Pegasus at the time Spain was hosting Sahrawi leader Brahim Ghali. Jabaroot now claims to have original material pertaining to this espionage activity, leaving the question of authenticity hanging in the air as the situation continues to unfold.

As reported by abc.es.