Death to Toll is an Australian extremist direct-action campaign aligned with the broader Palestine Action network. It targets Toll Group, Japan Post Holdings, and defense contractors associated with the Australian Defence Force based on the belief that those entities support Israel or the Israeli military. The campaign is part of a decentralized ecosystem of franchises, affiliates, offshoots, and partner groups that share ideological alignment, target selection, and operational methods with Palestine Action. The actor’s activity is characterized by vandalism, obstruction, and sabotage intended to impose financial, operational, and reputational costs on targeted organizations. Across the wider network, attacks are typically conducted by small cells, often outside business hours, and emphasize physical security breaches that enable interior damage. Common tradecraft associated with the network includes use of blunt-force sabotage, coordinated direct action, and operational security supported by encrypted communications and social media amplification. Instructional materials and training circulated within the broader movement have helped propagate these tactics internationally. Death to Toll should be understood as an Australian affiliate within a transnational militant activist network rather than as an isolated standalone group. Its targeting profile places logistics, shipping, defense-linked entities, and related public-sector organizations at elevated risk in Australia. The dominant motivation is influence operations: coercive direct action designed to pressure organizations to sever perceived ties to Israel and defense activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.