Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇱🇧 🇺🇸 🇮🇷 LB

Hezbollah

Also known ashezbollah

Hezbollah is a Lebanese militant and political organization founded in the early 1980s under the auspices of Iran’s Islamic Revolutionary Guard Corps (IRGC) and initially protected by Syria. The IRGC established a headquarters in Baalbek and trained local Shiite youth who formed Hezbollah’s core. The group evolved from a small Islamic militia into a powerful political party, social network, and military organization in Lebanon, while remaining part of Tehran’s proxy network; the IRGC Quds Force is described as maintaining relationships with proxy groups such as Hezbollah. The content attributes to Hezbollah early kidnappings and suicide bombings, including the 1983 bombings of US and French peacekeepers in Beirut that killed 241 US Marines and 58 French paratroopers. A US federal court in 2003 found Iran responsible for providing material support to Hezbollah for those bombings. Hezbollah also used social services, charity networks, and media operations including AlManar TV to build support and shape narratives of resistance and legitimacy. After Lebanon’s civil war, Syria allowed Hezbollah and Amal to retain their weapons despite disarmament requirements under the Taif Agreement. Hezbollah’s continued armed status, refusal to disarm after Israel’s 2000 withdrawal, and selective compliance with Lebanese state authority are described as undermining Lebanese sovereignty and contributing to sectarian polarization. The content describes Hezbollah as a transnational terrorist and militant actor with operational, logistical, and financial activity beyond Lebanon. Mentioned activities include surveillance of diplomatic targets in Bogotá, a failed bombing attempt in Bogotá linked to Hezbollah, ongoing cell activity and arrests in border regions such as Cúcuta, and a well-documented presence in the Tri-Border Area of Argentina, Brazil, and Paraguay for fundraising and logistical support. The group is also described as having involvement in criminal and financing networks, including international drug-trafficking activity referenced in connection with DEA Project Cassandra. Additional reporting in the content states that Spain, Germany, France, and the United Kingdom dismantled a Hezbollah drone smuggling ring in April 2025. Recent content also links Hezbollah to plots and networks in Gulf states. Lebanon’s Ministry of Foreign Affairs and Emigrants denounced Hezbollah’s involvement in a UAE terrorist plot, while the UAE’s State Security Apparatus said it dismantled a network funded and operated by Hezbollah and Iran that used a fake commercial enterprise as cover for money laundering, terrorism financing, and external operations. Kuwait separately announced in March that it had uncovered a terrorist group affiliated with Hezbollah and arrested 16 suspects; authorities said they seized firearms, ammunition, an assassination weapon, encrypted Morse communication devices, drones, maps, narcotics, cash, and terrorist flags and images. The content also states that Hezbollah has used cryptocurrency at increasing scale, alongside other Iran-linked proxies and designated terrorist organizations such as Hamas and the Houthis. Chainalysis reporting cited in the content states that Iran’s IRGC transacted more than $2 billion from sanctioned addresses and that Lebanese Hezbollah, Hamas, and the Houthis have used cryptocurrency at increasingly greater scale. Hezbollah is further described as active in regional conflict, including launching rockets and drones toward Israel and being part of the broader Iran-aligned “Axis of Resistance.” The content notes Hezbollah’s ability to conduct extraterritorial attacks outside Lebanon was almost certainly diminished in one assessment, but it remains identified as an Iranian proxy with military, propaganda, financing, and external operational capabilities. Known alias in the provided content: Hezbollah.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • LB
  • US
  • IR
MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics15 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
4 techniques
T1589×2
Gather Victim Identity Information
T1592
Gather Victim Host Information
T1593
Search Open Websites/Domains
T1593.001
Social Media
T1595
Active Scanning
TA0042
Resource Development
3 techniques
T1583×2
Acquire Infrastructure
T1583.005
Botnet
T1585
Establish Accounts
T1588
Obtain Capabilities
T1588.001
Malware
TA0002
Execution
1 technique
T1648
Serverless Execution
TA0005
Stealth
1 technique
T1036
Masquerading
TA0011
Command and Control
1 technique
T1573
Encrypted Channel
TA0040
Impact
2 techniques
T1486
Data Encrypted for Impact
T1531
Account Access Removal
ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.