Yemen Cyber Army is a pro-Houthi hacktivist group that emerged in 2015 during the Yemeni civil war. It is widely described as aligned with the Houthi movement and has also been characterized as an Iranian cyber proxy. The group is known primarily for politically motivated website defacements, anti-Saudi messaging, and data-leak operations targeting media and government entities. Early publicly associated activity included the defacement of a London-based Arabic newspaper and the compromise of the Saudi Ministry of Foreign Affairs, followed by the publication of large volumes of stolen diplomatic communications. The group’s operations have centered on unauthorized access to websites and online services, defacement for propaganda purposes, theft of internal communications and credentials, and public leaking of stolen data. Reported targeting has included Saudi government entities, Yemeni government institutions, media outlets, and at least one Israeli news outlet. More recent reporting also places the group among pro-Iranian hacktivist actors targeting Saudi Arabia amid heightened regional conflict. Yemen Cyber Army has been discussed in attribution research as an example of a hacktivist front whose infrastructure and tradecraft raised questions about possible overlap with more sophisticated state-linked activity, including speculation about links to Sofacy, but such linkage remains unconfirmed and should be treated cautiously. The actor’s observed behavior is consistent with hacktivist and proxy-style information operations rather than ransomware activity. Known activity supports capabilities in initial compromise, credential theft, data exfiltration, website defacement, and politically motivated disclosure of stolen information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist-style activity focused primarily on website breaches and defacements, with additional data theft/exfiltration and leaking of stolen records/credentials, emerging around the Yemeni civil war timeframe.
Hacktivist activity involving website intrusions/defacements and theft of login credentials/data, aligned with ideological/political objectives and historically supportive of the Houthis.
Hacktivist group described as an Iranian proxy aligned with the Houthis; associated with website defacements and politically/ideologically motivated intrusions.
Hacktivist group described as an Iranian proxy aligned with the Houthis; associated with website defacements and politically/ideologically motivated intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.