Skip to main content
Mallory
🇦🇫 AF

taliban

Also known astaliban

The Taliban is an Islamist militant group and de facto governing authority in Afghanistan. The provided content describes the Taliban as having returned to power in Afghanistan and ruling the country for nearly five years. It states that the group shelters regional and international terrorist organizations, with credible international reports indicating that at least 25 terrorist organizations are active in Afghanistan under the Taliban’s umbrella. The content also describes the Taliban as imposing harsh conditions on the Afghan population, particularly targeting women, Hazaras, Shiites, Hindus, and Sikhs; enforcing hijab restrictions; carrying out arrests; and being linked in reporting to torture, lethal violence against protesters, repression in provinces including Herat and Badakhshan, and exploitation of mineral resources. Additional mentions in the content associate Taliban warlords with heroin trafficking, describe Taliban responsibility for stopping bus passengers and killing them, identify Mawlawi Mohammed Islam Mohammadi as the Taliban’s former governor of Bamiyan when the Bamiyan Buddha statues were destroyed in 2001, and state that the Taliban blocked fiber connections in multiple provinces and was linked to a nationwide internet and telecommunications shutdown in Afghanistan. No aliases or sub-groups beyond "taliban" are provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇦🇫 Afghanistan

Where they're from

Attributed origin per open-source reporting.

  • AF
MITRE ATT&CK

Tradecraft

7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
4 techniques
T1583
Acquire Infrastructure
T1585
Establish Accounts
T1587
Develop Capabilities
T1588
Obtain Capabilities
TA0006
Credential Access
1 technique
T1056
Input Capture
TA0009
Collection
2 techniques
T1056
Input Capture
T1213
Data from Information Repositories
TA0040
Impact
1 technique
T1657
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping7

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.