Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Groups In Development

Dark Storm

Also known asDark Stormdark_storm_team

Dark Storm Team is a pro-Palestinian, anti-Israel hacktivist group active since late 2023 (also referred to as Dark Storm, DarkStorm, dark_storm_team, and MRHELL112). The group is described as targeting governments and organizations perceived as supporting Israel, and has targeted entities in the Middle East, Israel, the United States, and NATO countries. Reported activity includes large-scale distributed denial-of-service (DDoS) campaigns, website defacements, phishing campaigns, and claimed ransomware attacks. Multiple sources in the content describe its tactics as similar to those of the Russia-linked KillNet group, and one source notes the group has advertised itself as hackers-for-hire despite its political messaging. Within the provided reporting, Dark Storm Team repeatedly claimed disruptive operations, including responsibility for the March 10, 2025 DDoS attack on X/Twitter, and a claim that it took BreachForums offline via DDoS. The content also places the group among actors conducting disruptive operations against Western and Israeli targets, including claimed attacks on Israeli government ministries and services such as the Ministry of Justice, Police, Education, the Supreme Court, and monitoring/targeting of Israeli government ministry websites. Additional mentions describe targeting of Israeli banking, including Union Bank of Israel, and attacks on major U.S. airports and Snapchat. In broader regional conflict reporting, Dark Storm Team is listed among pro-Iranian or pro-Palestinian hacktivist ecosystems involved in low-level DDoS attacks, website defacements, and phishing campaigns, and among groups claiming operations during escalations involving Israel, Iran, and Western-aligned targets. The content does not independently verify all public claims.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics3 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
TA0040
Impact
2 techniques
T1486×2
Data Encrypted for Impact
T1498×6
Network Denial of Service
IOCS

Observables

6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables6

Domains, IPs, and hashes tied to this actor, refreshed continuously.