Dark Storm Team is a pro-Palestinian, Iran-aligned hacktivist collective active since late 2023 that operates in the broader anti-Israel and anti-West disruption ecosystem. The group is also tracked as DarkStorm, dark_storm, dark_storm_team, and darkstorm_team, and some reporting associates it with the handle MRHELL112. It has been repeatedly described as part of a loose coalition of resistance-branded and opportunistic actors that coordinate and amplify operations via Telegram alongside groups such as Cyber Islamic Resistance, 313 Team, Keymous+, DieNet, and at times pro-Russian actors including NoName057(16) and Killnet-linked networks. Dark Storm Team is primarily known for disruptive distributed denial-of-service operations, propaganda amplification, and symbolic targeting of governments, financial institutions, major online platforms, and other organizations perceived as supporting Israel or the West. Reported targeting has included Israeli government ministries, Israeli financial institutions, U.S. entities, NATO-country targets, and Western platforms. The group has also been cited in campaigns affecting Gulf states and European financial institutions during periods of geopolitical tension. Multiple reports characterize its tradecraft as relatively low sophistication and heavily reliant on DDoS activity, public claims, and wartime messaging rather than advanced intrusion capability. The actor has been linked to coordinated anti-Israel campaigns such as #OpIsrael and to broader Iran-aligned cyber mobilization following regional military escalations in 2025 and 2026. In those contexts, Dark Storm Team was described as contributing mainly DDoS activity and propaganda amplification within a larger coalition that shared target lists and synchronized claims. It has also been associated with low-level website defacements and phishing in some reporting. Several assessments place the group at the criminal-adjacent edge of the ecosystem, where hacktivist branding overlaps with commercial cybercrime behavior, including reported hackers-for-hire promotion, DDoS-for-hire activity, malware sales, and ransomware narratives or attacks. Its dominant public posture, however, remains politically motivated disruption tied to pro-Palestinian and anti-Israel messaging. Dark Storm Team has claimed responsibility for high-visibility service disruptions, including attacks against major social media and forum platforms, but self-attribution in such cases is not sufficient to independently confirm operational responsibility. Across reporting, the most consistently supported characteristics are disruptive DDoS operations, anti-Israel and anti-West targeting, coalition participation with other hacktivist brands, and a blend of ideological messaging with criminal-adjacent activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of the broader coalition; described as contributing DDoS activity and propaganda amplification.
Criminal-adjacent actor in the pro-Iran ecosystem blending DDoS activity, ransomware narratives, and wartime propaganda.
Conducting DDoS campaigns against European financial institutions, with activity peaking around elections and heightened political tension.
Hacktivist group coordinating with NoName057(16) on simultaneous attacks against Israeli financial institutions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.