Mr Hamza is a pro-Palestinian, anti-Israel hacktivist group that has also appeared in broader pro-Iranian and anti-India cyber campaigns. The group is associated primarily with disruptive operations, especially distributed denial-of-service activity, and has been described as aligned with Iranian interests in the context of regional cyber conflict. Reporting places it among IRGC-aligned hacktivist actors used for more disruptive actions, in contrast to Iranian intelligence-oriented espionage groups such as MuddyWater. Mr Hamza has also been cited among pro-Pakistan and anti-India hacktivist clusters active during periods of India-Pakistan tension, indicating participation in ideologically aligned coalition campaigns beyond the Israel-Iran theater. The group is known for targeting Israeli entities, including military suppliers, ports, and energy companies, and has been named in campaigns affecting government, critical infrastructure, and satellite-related targets. It has also been associated with disruptive operations against Israeli and allied interests during the 2025-2026 Israel-Iran escalation, and with claimed targeting of energy-sector organizations in Israel. In South Asia, it has been listed among groups attempting to target Indian cyberspace and participating in anti-India DDoS activity. Operationally, Mr Hamza is most strongly associated with DDoS campaigns and coalition-based hacktivism. The group has been linked to the Python-based Abyssal DDoS tool and to use of botnet-backed attack infrastructure. It has formed or participated in alliances with other hacktivist actors including Keymous+, AnonSec, Sylhet Gang-SG, Anonymous Kashmir, and others in coordinated anti-Israel, pro-Palestinian, pro-Iranian, or anti-India operations. It also helped amplify newer aligned actors by promoting DieNet at launch. Available reporting supports disruption and propaganda-oriented hacktivism as its core profile; broader intrusion or destructive claims are less consistently substantiated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named allied hacktivist group participating in strategic alliances and joint operations with Keymous+.
Established actor in the same hacktivist ecosystem that promoted DieNet at launch, helping provide visibility and credibility.
IRGC-aligned hacktivist group associated in the report with disruptive cyber actions as part of Iran’s broader two-tiered strategy combining espionage and sabotage.
Mr Hamza is a hacktivist group focused on anti-Israel and pro-Palestinian causes, known for developing and distributing DDoS tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.