al Qaeda
Al-Qaeda is a militant Islamist terrorist organization, also referred to in the content as "al Qaeda" and "the Base." The content states that the group called itself al Qaeda from about 1989 onward, and that it was founded by Usama Bin Ladin and Muhammed Atef. It is described as possessing a near-global network whose leaders publicly stated they would attack the United States, its institutions, and its citizens. The content explicitly attributes the September 11, 2001 attacks to Al-Qaeda and also attributes the August 7, 1998 U.S. embassy bombings in Nairobi, Kenya, and Dar es Salaam, Tanzania, to members and associates of Usama Bin Ladin’s Al-Qaeda organization. The content describes Al-Qaeda’s presence in East Africa beginning in 1993-1994 through operatives, NGOs, and commercial fronts in Kenya and Tanzania. Named operatives and associates in that reporting include Wadih El-Hage, Fazul Abdullah Mohammed, Mohammed Sadiq Odeh, Abdullah Ahmed Abdullah, Mohammed Rashed Daoud Al-Owhali, Jihad Mohammed Ali, Khalfan Khamis Mohammed, Ahmed Khalfan Ghailani, Abu Ubaida Al-Banshiri, and others. The Nairobi and Dar es Salaam bombings are described as involving safe houses, reconnaissance, bomb construction and storage, truck-borne explosives, and coordinated detonation. The content also references Al-Qaeda-linked threats against Pakistani Christians and reporting that Al-Qaeda and ISIS affiliates have expanded activity in Africa, including the Sahel. The content further describes Al-Qaeda as part of the broader global jihadist movement and repeatedly highlights its rivalry with ISIS for leadership of that movement. It states that Al-Qaeda formally disavowed ISIS on February 2, 2014, and references competition between ISIS and Al-Qaeda in multiple theaters, including the Caucasus, where the Islamic Emirate of the Caucasus is described as an Al-Qaeda affiliate. The content also references Jabhat al-Nusra in the context of this split. Regarding cyber-related activity, one cited report claims that leaders linked to Islamic State and Al-Qaeda were recruiting technically skilled radicals for cyber operations, seeking capabilities against U.S. government agencies, banks, energy companies, and transport systems, while investing in encryption technologies to protect communications. The content also states that the Global Islamic Media Front launched encryption software in 2007 for Al-Qaeda and other Islamic militant groups, and that an Al-Qaeda-affiliated media front later released an updated Android encryption application. Overall, the content portrays Al-Qaeda as a transnational jihadist terrorist organization with global reach, a history of mass-casualty attacks against U.S. interests, operational networks in regions including East Africa and Africa more broadly, public hostility toward the United States, and ongoing ideological and organizational competition with ISIS.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
Tradecraft
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Discussed as a long-standing jihadist network with affiliates active in the Sahel and historical roots in Africa dating back to the 1990s. The content notes that many current groups stem from al-Qaeda roots and that its affiliates often focus attacks on security forces.
Referenced as a terrorist organization with senior financial leadership targeted by U.S. operations and financial intelligence efforts after 9/11.
Transnational jihadist organization whose affiliates are expanding in Africa, including links to al-Shabab and militants threatening West African states such as Benin.
Referenced as another terrorist organization for comparison with Hamas; no specific operation discussed in the content.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.