Palestine Action is a UK-founded militant direct-action network established in 2020 that targets organizations it perceives as supporting Israel or the Israel Defense Forces. It was designated a terrorist organization in the United Kingdom in July 2025. The network is decentralized and operates through small activist cells, as well as franchises, affiliates, offshoots, and partner groups in Europe, North America, and Australia. Known associated entities include Palestine Action Italia, also known as Palestina Libera; Unity of Fields, formerly Palestine Action US; Death to Toll in Australia; and the partner group Shut the System. The network also distinguishes between overt direct-action activism and more covert militant elements such as Palestine Action Underground. Its operations have primarily focused on defense contractors, especially firms linked to military supply chains, but have also expanded to banks, insurance companies, logistics and shipping providers, government entities, and media organizations. Reported tactics center on vandalism, physical obstruction, and sabotage intended to impose financial and reputational costs. The most damaging incidents have involved physical security breaches enabling interior sabotage. The group’s methods, training materials, and instructional guidance have been disseminated across its international network, contributing to replication of its tactics abroad. Following its UK proscription, Palestine Action reportedly reduced sabotage activity and public attack claims inside the UK while encouraging aligned extremists and affiliated cells outside the UK to intensify operations. Its operational tempo has been closely tied to developments in the Israel-Hamas conflict, with surges following major events. The network uses social media and encrypted communications for coordination, propaganda, and claims of responsibility, and its decentralized structure complicates pre-attack detection. The actor’s activity is best characterized as ideologically driven militant direct action focused on coercive disruption and sabotage rather than financially motivated cybercrime or ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.