The Houthis, also known as Ansarallah, are an Iran-backed Yemeni militant group and designated terrorist organization referenced in the reporting as part of the broader Axis of Resistance. The content describes them as primarily operating in and from Yemen, controlling Sanaa and other territory, and conducting attacks against commercial shipping in the Red Sea as well as drone strikes against Saudi infrastructure, including the Abqaiq oil processing facility and the Khurais oil field. Reporting cited here also states that the Houthis have targeted global shipping lanes and that they were redesignated by the US Department of State as a Foreign Terrorist Organization on March 5, 2025. The content attributes to the Houthis the use of drones and UAV-related capabilities, including attacks on Saudi oil infrastructure and procurement of UAVs, drone components, and counter-drone systems via Chinese suppliers. It also states that GuardZoo surveillanceware has been tied to the Houthis. Multiple sources in the content describe Houthi use of cryptocurrency at increasing scale for weapons procurement, commodities procurement, and sanctions evasion. OFAC reporting cited here says that on April 2, 2025, it sanctioned a network of financial and logistical facilitators tied to the Iran-backed Houthis and identified eight cryptocurrency wallets used to support Houthi weapons procurement, commodities procurement, and sanctions evasion efforts; related reporting also references Houthi-linked facilitators such as Sa’id al-Jamal. The content further describes the Houthis as having issued media statements during the Israel-Iran conflict period, with some foreign terrorist organization statements calling for violence against US assets and personnel in the Middle East. Additional reporting cited here alleges Houthi involvement in undersea cable sabotage in the Red Sea in 2024 and notes a transactional or opportunistic relationship developing between al-Shabab and the Houthis in Yemen. The group is also described in one article as combining military operations with influence and propaganda efforts to gain legitimacy internationally.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses cryptocurrency to procure UAVs, drone components, and counter-drone systems via Chinese suppliers.
Accused of sabotaging undersea communication cables in the Red Sea between Saudi Arabia and Djibouti as part of Iran-aligned hybrid activity affecting regional digital infrastructure.
Use of cryptocurrency wallets to support procurement (weapons/commodities) and sanctions evasion, with financial facilitation linked to Iranian oil and logistics networks.
Described as an Iran-linked proxy/terrorist-designated group increasingly using cryptocurrency for transactions/financing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.