Dark Storm Team is a pro-Palestinian, anti-Israel hacktivist group active since late 2023 that operates within a broader ecosystem of Iran-aligned and opportunistic disruptive actors. It is commonly referenced as Dark Storm, DarkStorm Team, and DarkStorm, and has also been associated with the alias MRHELL112. The group is primarily known for politically motivated distributed denial-of-service operations, propaganda amplification, and disruptive campaigns against governments, financial institutions, and major online platforms perceived as aligned with Israel or the West. Reporting also places it in a looser proxy layer of the pro-Iran cyber ecosystem, alongside groups such as 313 Team, Cyber Islamic Resistance, Keymous+, and DieNet, with coordination and mutual amplification often occurring through Telegram-based mobilization and shared target lists. Dark Storm Team has repeatedly claimed attacks against Israeli government ministries, Israeli financial institutions, Western platforms, NATO-country targets, and U.S. organizations. It has been linked to coordinated #OpIsrael activity and to broader anti-Western campaigns, including disruptive operations against European financial institutions during periods of political tension. The group has also publicly claimed responsibility for high-visibility service disruptions, including attacks against major social media and forum platforms. Its targeting profile centers on symbolic and public-facing entities where outages generate psychological impact, media attention, and political messaging. The group’s tradecraft is assessed as comparatively low to moderate sophistication and heavily disruption-oriented. High-confidence reporting associates it with large-scale DDoS campaigns, website defacements, phishing activity, and propaganda-driven claim amplification. Dark Storm Team has also been described as operating at the criminal-adjacent edge of the hacktivist ecosystem, where wartime messaging overlaps with ransomware narratives and hackers-for-hire style positioning. Multiple reports state that the group has conducted ransomware attacks in addition to DDoS activity, although the available information does not establish a mature ransomware program comparable to dedicated extortion groups. Dark Storm Team’s operational role appears to be less about stealthy long-term intrusion and more about rapid mobilization, visible disruption, and coalition signaling during geopolitical crises. It has been described as using tactics similar to Killnet and as contributing primarily DDoS activity and propaganda amplification within broader anti-Israel and anti-Western campaigns. Its dominant motivation is ideological and geopolitical rather than purely criminal, even where its branding and tactics overlap with criminal ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of the broader coalition; described as contributing DDoS activity and propaganda amplification.
Criminal-adjacent actor in the pro-Iran ecosystem blending DDoS activity, ransomware narratives, and wartime propaganda.
Conducting DDoS campaigns against European financial institutions, with activity peaking around elections and heightened political tension.
Hacktivist group coordinating with NoName057(16) on simultaneous attacks against Israeli financial institutions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.