The Houthis, also known as Ansar Allah or Ansarallah, are a Yemeni armed movement and de facto governing authority over large parts of northern Yemen, including Sanaa. They are widely assessed as an Iran-backed militant and political actor and have been designated as a terrorist organization by multiple governments at different times. The group emerged from Yemen’s Zaydi revivalist movement and evolved into a major insurgent force in the Yemeni civil war, fighting the internationally recognized Yemeni government and a Saudi-led coalition since 2015. The Houthis are known for combining insurgent warfare, missile and unmanned aerial vehicle operations, maritime coercion, propaganda, and transnational facilitation networks. They have repeatedly targeted Saudi and Emirati interests with drones and missiles, including major Saudi energy infrastructure. They have also conducted sustained attacks against commercial shipping and naval targets in and around the Red Sea and Bab al-Mandeb, creating significant disruption to international maritime trade and regional energy flows. Reporting also attributes to the group attempted or alleged attacks affecting broader critical infrastructure, including undersea communications cables, though such claims are not always independently confirmed. Operationally, the group has demonstrated the ability to employ ballistic missiles, cruise missiles, one-way attack drones, maritime threats, and layered targeting against vessels and fixed infrastructure. Their maritime campaign has included attacks on commercial vessels, declared blockades, and selective signaling around which ships may transit safely, reflecting both coercive intent and political messaging. The Houthis have also paired kinetic operations with information operations designed to frame themselves as a legitimate regional resistance actor rather than solely a Yemeni insurgent movement. Financially and logistically, the Houthis have relied on support networks tied to Iran and to facilitators operating across shipping, commodities, and sanctions-evasion ecosystems. Public sanctions actions have linked Houthi-associated networks to procurement of weapons and dual-use goods, movement of commodities, and use of cryptocurrency for financing and procurement. Reporting has also described Houthi use of digital assets to support acquisition of military-related equipment, including unmanned systems components and counter-drone capabilities. The group is frequently discussed alongside other Iran-aligned actors in the so-called Axis of Resistance, including Hezbollah, Hamas, and Iraqi Shi'a militias. While the Houthis have issued threats and media statements connected to regional conflicts and have targeted international commerce in the Middle East, available reporting in this context indicates they have generally prioritized regional military and maritime targets over conducting terrorist attacks inside the United States. The movement’s leadership is centered on the al-Houthi family, with Abdulmalik al-Houthi serving as its best-known leader. The Houthis have also been accused of repression in areas under their control, including detention and abuse of political opponents, journalists, minorities, and international personnel. Overall, the Houthis represent a hybrid militant, political, and quasi-state actor whose significance extends beyond Yemen through missile and drone warfare, maritime disruption, sanctions evasion, and alignment with Iranian regional strategy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Resumed maritime and missile attacks in the Red Sea/Saudi theater, targeting vessels and Saudi energy infrastructure while enforcing a declared blockade against Saudi-linked shipping, with apparent carve-outs for Chinese- and Russian-linked vessels.
Uses cryptocurrency to procure UAVs, drone components, and counter-drone systems via Chinese suppliers.
Accused of sabotaging undersea communication cables in the Red Sea between Saudi Arabia and Djibouti as part of Iran-aligned hybrid activity affecting regional digital infrastructure.
Use of cryptocurrency wallets to support procurement (weapons/commodities) and sanctions evasion, with financial facilitation linked to Iranian oil and logistics networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.