Houthis
The Houthis, also known as Ansarallah, are an Iran-backed militant group in Yemen. The provided content describes them as an Iran-backed proxy or militia and, in some sources, as a terrorist organization or foreign terrorist organization. They control Yemen’s capital Sanaa and other territory. Based on the content, the Houthis have targeted commercial shipping in the Red Sea for months, contributing to regional instability and disruption of international commerce. They have also been linked to drone attacks on Saudi oil infrastructure, including the Abqaiq oil processing facility and the Khurais oil field, and to earlier attacks on the East-West Pipeline and the Shaybah oil field. The content further states that Houthi-linked financial infrastructure enabled missile attacks, drone strikes, and Red Sea disruptions. The content states that the Houthis have used cryptocurrency at increasing scale. TRM Labs documented their use of cryptocurrency to procure UAVs, drone components, and counter-drone systems via Chinese suppliers. OFAC sanctioned a network of financial and logistical facilitators tied to the Houthis on April 2, 2025, including eight cryptocurrency wallets used to support weapons procurement, commodities procurement, and sanctions evasion. Those wallets reportedly moved nearly $1 billion in illicit funds and interacted with wallets linked to previously sanctioned facilitator Sa’id al-Jamal. The content also notes OFAC’s December 2024 update to the designation of IRGC-connected Houthi financier Sa’id al-Jamal to include crypto wallets used for money laundering and illicit shipping of Iranian oil on behalf of the Houthis. The content also references broader facilitation and external support networks. It states that Russia-based actors and shipping entities facilitated arms movement, stolen Ukrainian grain shipments from Crimea to Yemen, and illicit payments supporting the Houthis. It also states that the Houthis have used mainstream exchanges as cash-out points and deposit addresses at sanctioned exchange Garantex. Chainalysis is cited as assessing that Iran-linked proxies and designated terrorist organizations including the Houthis have used cryptocurrency at increasingly greater scale. Additional activity attributed to or associated with the Houthis in the content includes statements calling for violence against U.S. assets and personnel in the Middle East; an opportunistic or transactional relationship with al-Shabab in Yemen; alleged cutting of submarine communication cables in the Red Sea in 2024; and GuardZoo surveillanceware tied to the Houthis. One article in the content also alleges that the Houthis benefited from Chinese-sourced weapons components, Russian satellite intelligence for maritime targeting, and diplomatic cover, and that they negotiated safe passage for Russian and Chinese vessels through the Red Sea, but these points are presented as allegations in the source material. Known alias in the provided content: Ansarallah.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Military
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses cryptocurrency to procure UAVs, drone components, and counter-drone systems via Chinese suppliers.
Accused of sabotaging undersea communication cables in the Red Sea between Saudi Arabia and Djibouti as part of Iran-aligned hybrid activity affecting regional digital infrastructure.
Use of cryptocurrency wallets to support procurement (weapons/commodities) and sanctions evasion, with financial facilitation linked to Iranian oil and logistics networks.
Described as an Iran-linked proxy/terrorist-designated group increasingly using cryptocurrency for transactions/financing.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.