WildCard is a Hamas-linked threat actor associated with malware operations targeting Israeli entities during the cyber activity surge surrounding the Gaza conflict in late 2023. The group has been publicly linked to deployment of a Rust-based variant of the SysJoker backdoor, a cross-platform malware family used for covert access and post-compromise control. In observed activity, the Rust variant used cloud-service-based command-and-control mechanisms, indicating an emphasis on stealth and operational resilience. WildCard’s known activity aligns with politically motivated intrusion operations against Israeli targets rather than financially motivated crime. The group is notable for using custom or adapted malware rather than relying solely on disruptive hacktivist techniques such as defacement or denial-of-service. Based on the available reporting, WildCard is best characterized as a Hamas-linked intrusion actor focused on gaining and maintaining unauthorized access to victim environments in Israel. Publicly supported reporting in this context does not establish broader victimology, sub-groups, or a wider geographic targeting pattern beyond Israeli entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.