Muslim Cyber Army is a pro-Palestinian hacktivist group active in cyber operations associated with the October 2023 Israel-Hamas conflict. Publicly attributed activity consists primarily of claimed attacks against Israeli targets, including overlap with claims made by Ghosts of Palestine against the Israeli Ministry of Education and separate claims involving the exposure of Israeli citizens’ personal data. Reporting characterizes the group as part of a broader wave of low-sophistication, attention-seeking hacktivist actors that relied heavily on public claims, with some alleged breach evidence assessed as potentially forged, out of context, or derived from previously exposed data. The group is therefore best understood as a hacktivist actor focused on anti-Israel messaging and claimed data-breach activity rather than a demonstrably advanced intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Palestinian hacktivist group claiming attacks and personal data theft against Israeli targets, though supporting evidence may be forged or recycled.
Muslim Cyber Army is a pro-Palestine hacktivist group focused on breaching and leaking personal data of Israeli citizens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.