Hunt3r Kill3rs is a pro-Palestine hacktivist collective described as having French-Moroccan roots and operating within the broader pro-Iranian “Resistance Axis” cyber ecosystem. The group functions as a bridge between Moroccan cyber crews and the Cyber Islamic Resistance coordination umbrella, aligning it with a wider network of state-linked and proxy actors engaged in disruptive and influence-oriented cyber activity. The group is associated primarily with disruptive operations rather than stealth espionage or ransomware. Reported tradecraft includes botnet-driven distributed denial-of-service activity, weaponization of publicly known vulnerabilities for offensive use, and participation in exploit sales. Hunt3r Kill3rs has also been identified as amplifying disruption claims against Israeli targets during periods of regional escalation. Its role appears to center on scalable nuisance and pressure operations, propaganda amplification, and support to coordinated campaigns conducted by allied hacktivist and proxy groups. Known aliases include hunt3rkill3rs and hunt3r_kill3rs. Hunt3r Kill3rs is part of a broader ecosystem that includes Cyber Islamic Resistance and other aligned collectives, with activity framed around pro-Palestinian and anti-Israeli objectives. Based on the available facts, the group is best characterized as a politically aligned hacktivist actor focused on disruption, publicity, and coalition support rather than covert intelligence collection or financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.