Hezi Rash, meaning "Black Force," is a Kurdish nationalist hacktivist group reportedly established in 2023. The group presents itself as a digital defender of Kurdish society and conducts politically and religiously motivated cyber operations against countries and organizations it perceives as hostile to Kurdish or Muslim communities. Its activity is associated with hacktivism rather than espionage or financially motivated intrusion. Hezi Rash is primarily known for distributed denial-of-service operations. Between August and October 2025, it was linked to roughly 350 claimed DDoS attacks, an unusually high tempo for a group of its apparent size. Reported targets have included entities in Japan, Türkiye, Israel, Germany, Iran, Iraq, Azerbaijan, Syria, and Armenia. Publicly described campaigns include retaliatory attacks tied to perceived insults to Kurdish symbols and participation in anti-Israel hacktivist activity. The group has been linked to other hacktivist collectives including Keymous+, Killnet, and NoName057(16), with these relationships assessed as pragmatic alliances rather than evidence of shared ideology. Its operations reportedly leverage DDoS-as-a-Service infrastructure and publicly available attack tooling to amplify impact. Hezi Rash also maintains a visible propaganda and coordination presence across major social platforms and messaging channels, consistent with modern hacktivist mobilization and claim-and-amplify behavior. Hezi Rash is best characterized as an ideologically driven disruptive actor focused on service interruption and symbolic retaliation. High-confidence reporting supports DDoS as its core operational capability; there is no strong corroborated evidence here of broader intrusion tradecraft such as credential theft, persistence, or data extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hezi Rash is a Kurdish nationalist hacktivist group conducting DDoS attacks against countries perceived as hostile to Kurdish or Muslim communities.
Hezi Rash is a nationalist hacktivist collective established in 2023, conducting DDoS attacks against countries perceived as threats to Kurdish or Muslim communities. The group is highly active, leveraging alliances with other hacktivist groups and DDoS-as-a-Service platforms to increase its attack capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.