Hezbollah, also spelled Hizballah, is a Lebanon-based Shi'a Islamist political movement and armed organization backed by Iran. It is a core member of Iran's Axis of Resistance and maintains an extensive military capability directed principally against Israel, including rockets, anti-tank weapons, and unmanned aerial systems. Hezbollah has used FPV drones against Israeli troops in Lebanon and historically exploited intercepted Israeli unmanned-aircraft video feeds to support operational planning, including the 1997 Ansariya ambush. The organization also operates propaganda infrastructure, including the Al-Manar television network, and has been identified as participating in influence campaigning. Hezbollah-linked networks have been associated with overseas logistics, fundraising, intelligence collection, and surveillance activities, including activity in Latin America and surveillance of diplomatic targets in Colombia. Hezbollah is widely designated as a terrorist organization or subject to terrorism-related sanctions by numerous governments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of a wider set of foreign actors engaged in election-related influence campaigning.
Its Al-Manar broadcaster was identified on piracy-based internet television services carrying terrorist-linked content.
A long-standing terrorist proxy identified as part of Iran's threat network.
An Iran-aligned Lebanese proxy discussed in connection with terrorist violence and Iran's indirect, cut-out-based operations against Jewish targets during the war.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.