Hamas is a Palestinian Sunni Islamist militant and political organization based primarily in the Gaza Strip, with its military wing commonly known as the Izz ad-Din al-Qassam Brigades. It is widely designated as a terrorist organization by multiple governments. Hamas seized control of Gaza in 2007 and has since been a central belligerent in the Israel-Gaza conflict. The group’s stated hostility toward Israel and its long-running armed campaign have included mass-casualty attacks, rocket fire, cross-border assaults, hostage-taking, propaganda operations, and international support and financing activity. Hamas carried out the 7 October 2023 attack on Israel, in which militants entered Israeli territory by land, air, and sea, killed large numbers of civilians and security personnel, and abducted hostages into Gaza. Reporting in the supplied material also links Hamas to threats to execute hostages, efforts to reactivate dormant operational networks in Europe after October 2023, and financing activity involving foreign supporters, including cryptocurrency-based fundraising and transfers. The organization has long benefited from Iranian financial, military, and technical support. This support has included weapons expertise, technology transfer, training, and assistance relevant to rockets, explosives, and unmanned systems. Hamas has also been associated with the use of cryptocurrency to raise and move funds and to help procure military-related equipment such as UAVs, drone components, and counter-drone systems. In addition to kinetic operations, Hamas has engaged in information and media operations, including a reported satellite broadcast hijacking used to disseminate threats and propaganda to Israeli viewers. Operationally, Hamas demonstrates capabilities spanning initial access and post-compromise activity in the broader militant sense, including hostage-taking, exfiltration of captives, propaganda dissemination, financing, and procurement. In the cyber-adjacent domain, the supplied material supports spoofing through broadcast hijacking and the use of online and financial infrastructure for support activity, but does not provide high-confidence evidence for a broader standalone cyber intrusion program attributable to Hamas in this dataset. Hamas’s dominant motivation is ideological and political violence aligned with terrorism rather than financial gain or espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sought to extend its operational reach into Europe by activating dormant networks and supporting plots against Jewish and Israeli targets.
Received and sent funds through A7-linked cryptocurrency channels as a sanctioned counterparty excluded from the formal financial system.
Uses cryptocurrency to procure military equipment including UAVs, drone components, and counter-drone systems via suppliers in China.
Referenced as an aligned entity producing statements and videos disseminated online in support of IRGC-linked propaganda ecosystems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.