Moroccan Black Cyber Army is a pro-Palestinian, pro-Iran-aligned hacktivist group assessed to operate from Morocco and to participate in broader coalition activity under the Cyber Islamic Resistance umbrella. The group emerged in conflict-driven cyber campaigns tied to the Israel-Hamas war and later appeared in the wider Iran-Israel-U.S. escalation, where it was identified among globally distributed hacktivist actors aligned with Tehran’s proxy-oriented cyber ecosystem. The group has publicly claimed disruptive operations against Israeli targets, including attacks framed as service disruption against Israeli communications and online services, as well as alleged theft of sensitive Israeli documents. Reporting associates it with telecom-layer and communications-sector targeting in Tel Aviv. Its observed tradecraft is consistent with low-sophistication hacktivist operations centered on publicly claimed disruption and opportunistic data-theft assertions rather than demonstrated advanced intrusion capability. As with many actors in this ecosystem, some claims were made in a propaganda-heavy environment where independent verification was limited. Moroccan Black Cyber Army is best understood as part of a deniable, ideologically motivated hacktivist layer within a broader pro-Iran cyber coalition that includes actors from North Africa, South Asia, and the Middle East. Its activity has focused on Israeli entities and has supported anti-Israel messaging aligned with Palestinian solidarity narratives and the Axis of Resistance information environment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group within the CIR coalition focused on telecom-sector disruption against Israeli communications targets.
Hacktivist group making unsubstantiated claims of DDoS and document theft against Israeli targets.
Moroccan hacktivist actor conducting DDoS and defacement-style operations against Israeli telecom and banking targets, often using exaggerated compromise language.
Pro-Iran hacktivist group operating from Morocco as part of Iran’s globalized recruitment ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.