ThreatSec is a hacktivist threat actor active at least by 2023 and publicly associated with pro-Palestinian cyber operations during the Israel–Hamas war. The group has been linked to disruptive and intrusive activity rather than financially motivated ransomware operations. A reported operation attributed to ThreatSec involved breaching and shutting down systems belonging to Alfanet, a major Palestinian internet service provider, indicating willingness to conduct destructive or service-disrupting attacks against communications infrastructure. ThreatSec has also been identified as associated with other hacktivist collectives. It was named as part of an alliance formed in August 2023 alongside SiegedSec, Ghost Security, BlackForums, and Stormous Ransomware, and it was later described by KittenSec as an associated operation. These associations place ThreatSec within a broader ecosystem of loosely aligned hacktivist and cybercriminal actors that collaborate, cross-promote operations, and participate in politically charged campaigns. Available reporting supports characterization of ThreatSec as a hacktivist actor engaged in unauthorized network intrusion and disruptive post-compromise activity. High-confidence evidence directly ties it to breach activity and operational disruption of a telecommunications target. Broader geopolitical context places the group within conflict-driven cyber activity surrounding Israel and Palestine, but publicly available details on its internal structure, tooling, origin, and full victimology remain limited.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Member of the 'Five Families' alliance with SiegedSec and other groups, which collectively claimed multiple breaches before becoming inactive.
Hacktivist group claiming to have breached and shut down a major Palestinian ISP provider.
Pro-Israeli hacktivist activity; reportedly conducted a destructive intrusion against Palestinian ISP Alfanet, shutting down servers.
Referenced as an associated hacktivist operation linked by KittenSec in the context of planned targeting of additional NATO countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.