The Houthis, also known as Ansar Allah, are a Yemen-based armed movement that controls Sanaa and other areas of Yemen. The group is widely described as Iran-backed and has been designated by the United States as a Foreign Terrorist Organization. Its operations have included missile and uncrewed-aerial-vehicle attacks against Saudi Arabian energy infrastructure, including major oil-processing and oil-field facilities, as well as attacks on Saudi-linked and other commercial shipping in the Red Sea and Bab el-Mandeb region. These maritime attacks have disrupted shipping routes and contributed to commercial vessels diverting around the Cape of Good Hope. The movement has also used international financial, logistics, shipping, and cryptocurrency infrastructure to support weapons and commodities procurement. U.S. sanctions actions have identified Houthi-associated cryptocurrency activity used for procurement and sanctions evasion, including relationships with sanctioned facilitator Sa’id al-Jamal and Russia-based logistical facilitators. The group has issued messaging calling for violence against U.S. assets and personnel in the Middle East in the context of regional conflict.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developing missile capabilities with AI-assisted coding and simulation. The reported activity includes reinforcement-learning-assisted flight-control tuning and troubleshooting following an apparently unsuccessful guided-rocket test.
Uses cryptocurrency to procure dual-use goods for UAV and counter-UAV capabilities, including equipment sourced through a Russian broker reselling Chinese-made systems.
Attacking or threatening Saudi-linked shipping in Bab el-Mandeb and the Red Sea, driving rerouting and dark AIS transits.
Resumed maritime and missile attacks in the Red Sea/Saudi theater, targeting vessels and Saudi energy infrastructure while enforcing a declared blockade against Saudi-linked shipping, with apparent carve-outs for Chinese- and Russian-linked vessels.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.