ISIS, also known as the Islamic State of Iraq and Syria, is a jihadist terrorist organization that emerged from Iraq and Syria and at times controlled territory in the Middle East. It is widely designated as a terrorist organization and has operated through both centralized structures and increasingly decentralized regional cells and facilitators. Known aliases include Islamic State of Iraq and Syria and ISIS. The organization has relied on transnational financial facilitation networks spanning the Middle East, Europe, and West Africa. Documented support activity includes the use of money service businesses, hawala-style transfer mechanisms, currency exchange businesses, and cryptocurrency to move funds for ISIS-linked actors and affiliates. This demonstrates established capability in covert financial movement, use of intermediaries, and adaptation to counterterrorism pressure through decentralized support infrastructure. ISIS supporters and facilitators have also been linked to providing instructional material related to explosives, reflecting the group’s association with terrorist violence and operational enablement beyond simple fundraising. Recent enforcement actions indicate that sustained pressure has pushed ISIS toward greater dependence on geographically distributed facilitators rather than overt territorial administration. Based on the available facts here, the strongest supported characterization is a terrorist actor with transnational financing and support networks rather than a ransomware or cyber intrusion actor. High-confidence evidence in this record supports financial facilitation, covert movement of funds, and use of cryptocurrency, but does not directly support broader cyberattack lifecycle behaviors such as intrusion, persistence, or data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A terrorist organization using money service businesses and cryptocurrency facilitators to move funds across Europe, the Middle East, and West Africa, including support to its West Africa affiliate.
Referenced as a comparative example of a murderous terrorist organization similar in brutality to Hamas; no specific operation discussed in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.