Moroccan Black Cyber Army is a pro-Iran, anti-Israel hacktivist group assessed to operate from Morocco and to participate in the Cyber Islamic Resistance coalition. It has been identified as part of the broader globally distributed ecosystem of ideologically aligned proxy and hacktivist actors mobilized around the Israel-Palestine conflict and wider Iran-aligned cyber campaigns. The group has publicly claimed disruptive operations against Israeli targets, including telecom-layer targeting in Tel Aviv and attacks against Israeli online services. Reported activity includes claimed service disruption and alleged theft of sensitive Israeli documents. Its observed tradecraft is consistent with coalition-style hacktivist operations centered on disruptive attacks and opportunistic post-compromise publicity rather than sophisticated, independently verified intrusion sets. High-confidence reporting ties the group to anti-Israel targeting and to the Cyber Islamic Resistance umbrella, which coordinates campaigns across Israel and other regional adversaries of Iran. Moroccan Black Cyber Army appears to function as an ideologically motivated participant in a broader pro-Iran influence and disruption ecosystem rather than as a known state APT. Its activity aligns with hacktivist patterns such as claimed service disruption, targeting of communications-related entities, and public amplification of alleged breaches for propaganda effect.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group within the CIR coalition focused on telecom-sector disruption against Israeli communications targets.
Moroccan hacktivist actor conducting DDoS and defacement-style operations against Israeli telecom and banking targets, often using exaggerated compromise language.
Pro-Iran hacktivist group operating from Morocco as part of Iran’s globalized recruitment ecosystem.
Moroccan Black Cyber Army is a hacktivist group targeting Israeli organizations for data theft and leaks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.