Skip to main content
Mallory

al Qaeda

Also known asal Qaeda

Al-Qaeda is a militant Islamist terrorist organization, also referred to in the content as "al Qaeda" and "the Base." The content states that the group called itself al Qaeda from about 1989 onward, and that it was founded by Usama Bin Ladin and Muhammed Atef. It is described as possessing a near-global network whose leaders publicly stated they would attack the United States, its institutions, and its citizens. The content explicitly attributes the September 11, 2001 attacks to Al-Qaeda and also attributes the August 7, 1998 U.S. embassy bombings in Nairobi, Kenya, and Dar es Salaam, Tanzania, to members and associates of Usama Bin Ladin’s Al-Qaeda organization. The content describes Al-Qaeda’s presence in East Africa beginning in 1993-1994 through operatives, NGOs, and commercial fronts in Kenya and Tanzania. Named operatives and associates in that reporting include Wadih El-Hage, Fazul Abdullah Mohammed, Mohammed Sadiq Odeh, Abdullah Ahmed Abdullah, Mohammed Rashed Daoud Al-Owhali, Jihad Mohammed Ali, Khalfan Khamis Mohammed, Ahmed Khalfan Ghailani, Abu Ubaida Al-Banshiri, and others. The Nairobi and Dar es Salaam bombings are described as involving safe houses, reconnaissance, bomb construction and storage, truck-borne explosives, and coordinated detonation. The content also references Al-Qaeda-linked threats against Pakistani Christians and reporting that Al-Qaeda and ISIS affiliates have expanded activity in Africa, including the Sahel. The content further describes Al-Qaeda as part of the broader global jihadist movement and repeatedly highlights its rivalry with ISIS for leadership of that movement. It states that Al-Qaeda formally disavowed ISIS on February 2, 2014, and references competition between ISIS and Al-Qaeda in multiple theaters, including the Caucasus, where the Islamic Emirate of the Caucasus is described as an Al-Qaeda affiliate. The content also references Jabhat al-Nusra in the context of this split. Regarding cyber-related activity, one cited report claims that leaders linked to Islamic State and Al-Qaeda were recruiting technically skilled radicals for cyber operations, seeking capabilities against U.S. government agencies, banks, energy companies, and transport systems, while investing in encryption technologies to protect communications. The content also states that the Global Islamic Media Front launched encryption software in 2007 for Al-Qaeda and other Islamic militant groups, and that an Al-Qaeda-affiliated media front later released an updated Android encryption application. Overall, the content portrays Al-Qaeda as a transnational jihadist terrorist organization with global reach, a history of mass-casualty attacks against U.S. interests, operational networks in regions including East Africa and Africa more broadly, public hostility toward the United States, and ongoing ideological and organizational competition with ISIS.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
MITRE ATT&CK

Tradecraft

32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics38 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589×3
Gather Victim Identity Information
T1595×5
Active Scanning
TA0042
Resource Development
4 techniques
T1583×3
Acquire Infrastructure
T1583.008
Malvertising
T1585×4
Establish Accounts
T1585.001
Social Media Accounts
T1587×3
Develop Capabilities
T1588×2
Obtain Capabilities
T1588.001
Malware
TA0001
Initial Access
5 techniques
T1078
Valid Accounts
T1133
External Remote Services
T1190
Exploit Public-Facing Application
T1199×2
Trusted Relationship
T1659
Content Injection
TA0003
Persistence
2 techniques
T1078
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
5 techniques
T1027×2
Obfuscated Files or Information
T1036×3
Masquerading
T1070
Indicator Removal
T1078
Valid Accounts
T1564
Hide Artifacts
TA0006
Credential Access
2 techniques
T1040
Network Sniffing
T1056
Input Capture
TA0007
Discovery
1 technique
T1040
Network Sniffing
TA0009
Collection
3 techniques
T1056
Input Capture
T1074
Data Staged
T1114
Email Collection
TA0011
Command and Control
5 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1105×2
Ingress Tool Transfer
T1573×2
Encrypted Channel
T1659
Content Injection
TA0010
Exfiltration
1 technique
T1537
Transfer Data to Cloud Account
TA0040
Impact
4 techniques
T1486
Data Encrypted for Impact
T1489
Service Stop
T1498×2
Network Denial of Service
T1657
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping32

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.