Mr Hamza Cyber Force is a hacktivist group observed participating in coordinated pro-Palestinian and pro-Iranian cyber activity during 2025. The group has been publicly identified alongside Keymous+, Inteid, and Anonymous Kashmir as part of a more organized wave of hacktivist operations that relied on public alliances, resource sharing, and coordination through Telegram. This behavior reflects a shift from loosely organized online activism toward more structured coalition-based cyber campaigning. Available reporting supports characterization of Mr Hamza Cyber Force as an ideologically motivated actor operating within a broader hacktivist ecosystem shaped by geopolitical conflict. Its known activity is defined primarily by coordination, alliance-building, and participation in collective campaigns rather than by a uniquely documented malware family, intrusion set, or victimology profile attributable solely to the group. No high-confidence evidence in the available material establishes specific victim countries, industry verticals, or a distinct ransomware or extortion program directly operated by this actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.