Shut the System is a UK-based extremist direct-action group described as an environmental violent extremist offshoot linked to Extinction Rebellion that later collaborated on pro-Palestinian actions alongside Palestine Action. It appears to function as a partner group within a broader decentralized militant direct-action ecosystem focused on entities perceived to support Israel. Within that milieu, operations are typically conducted by small autonomous cells and emphasize vandalism, physical obstruction, and sabotage intended to impose financial and reputational costs on targets. Reported target categories across the associated network include defense contractors, banks, insurance companies, logistics providers, shipping firms, and some public-sector entities. The group’s activity is associated with ideologically driven direct action rather than financially motivated crime, and its collaboration pattern indicates alignment with anti-Israel militant activism in the UK.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.