The Al-Qassam Brigades are the military wing of Hamas and are involved in cyber-enabled terrorist financing activity in support of Hamas operations. Public reporting ties the group to organized cryptocurrency fundraising campaigns that used official web and social media channels to solicit donations, promote the use of cryptocurrency as difficult to trace, and provide operational guidance to donors. Investigations by U.S. and Israeli authorities linked these campaigns to laundering and movement of funds through numerous cryptocurrency accounts, intermediary wallets, exchanges, and money services businesses across multiple blockchain networks. In the available reporting, the group’s cyber-related activity is centered on fundraising, financial facilitation, and concealment of donation flows rather than intrusion operations. Authorities have attributed donation campaigns associated with the Al-Qassam Brigades to multiple cryptocurrencies and identified named individuals connected to those campaigns. The group is a component of Hamas and operates in the context of the Israel-Hamas conflict. Known naming in the supplied material includes Al Qassam Brigades and AQB.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Military wing of Hamas whose associated cryptocurrency wallets were included in the seizure tied to donation campaigns.
Conducting online cryptocurrency fundraising and laundering to support terrorist operations, using official websites and social media to solicit bitcoin donations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.