Boko Haram is a Nigeria-based Islamist terrorist organization active primarily in northeastern Nigeria and the Lake Chad Basin. The group is widely associated with mass-casualty attacks, abductions, forced conversions, coercion of children into combat roles, and systematic violence against civilians and family units. Its operations have made it one of the most significant insurgent threats in West Africa. ISWAP is referenced as a related faction in the same conflict environment. Recent reporting indicates Boko Haram has adapted consumer AI tools for operational support rather than propaganda alone. Former members stated that the group used mainstream AI chatbots for bomb-making, explosive-device design, attack planning, weapons troubleshooting, surveillance and movement-related questions, and other day-to-day battlefield problem solving. Members reportedly received internal training on chatbot use, and specialized units were formed to improve operational use of these systems. Outside trainers reportedly linked to the Islamic State network also taught members to use encryption tools, VPNs, and methods to bypass chatbot safety restrictions. Available reporting states that chatbot safeguards were circumvented in some cases. While claims that AI measurably improved operational effectiveness remain inconclusive, the group’s institutional adoption of such tools indicates deliberate experimentation with emerging technology in support of violent operations. Boko Haram has also exploited civilian harm and insecurity for recruitment in northeastern Nigeria. The group’s tactics and conduct support characterization as a terrorist actor motivated by ideological violence. High-confidence reporting in this dataset supports capabilities including initial access through coercive and violent action, reconnaissance and surveillance-related activity, operational planning, defense evasion through use of encryption and bypass methods, and destructive and lethal post-compromise activity centered on terrorism rather than financially motivated cybercrime or ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a related-content teaser as a terrorist group reportedly using frontier AI.
Using mainstream AI chatbots to support terror operations, including bomb-making, attack planning, propaganda, operational support, weapons troubleshooting, surveillance, movement planning, and internal training on bypassing safety restrictions.
Militant group operating in Nigeria that is described as leveraging commercial AI models to support weapons troubleshooting, attack planning, and explosive design.
Using chatbots/AI assistants for attack planning, weapons troubleshooting, and explosive-device design, including attempts to bypass safeguards and using Grok as a knowledge source for weapons handling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.