Hider Nex, also known as Tunisian Maskers Cyber Force and stylized as Hider_Nex, is a Tunisian hacktivist collective aligned with pro-Palestinian messaging. The group emerged in 2025 and became active in the 2026 Iran-Israel-US cyber conflict, where it participated in broader anti-Israel and anti-West disruptive campaigns alongside other hacktivist and state-aligned ecosystems. It has been described as part of a wider coalition that included pro-Iran and pro-Russian actors, and it publicly announced an alliance with NoName057(16). Hider Nex has been associated with coordinated operations against Kuwaiti government targets and with broader symbolic targeting tied to geopolitical events. The group’s tradecraft is centered on disruptive operations, especially distributed denial-of-service attacks, and it has also been described as using a hack-and-leak model that combines service disruption with data-breach claims or leaked data to amplify political messaging. Reported activity indicates a focus on government-sector targets in the Middle East, particularly Kuwait, during the March 2026 escalation. Hider Nex appears to operate primarily as a hacktivist propaganda and disruption actor rather than a highly sophisticated intrusion set, using cyber operations to support ideological and geopolitical narratives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of the broader coalition supporting pro-Iran cyber mobilization.
Actor that conducted broad targeting of Kuwaiti entities during the escalation.
Tunisian-flagged disruptive actor that allied with NoName057(16) and launched broad DDoS sweeps against Kuwaiti and South Korean government infrastructure.
Pro-Palestinian hacktivist collective combining DDoS and data breaches to amplify geopolitical messaging; cited as initiating the first recorded attack in the described period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.