ISIS-K, also known as ISIL-K or Islamic State Khorasan Province, is a jihadist terrorist organization and regional branch of the Islamic State that operates primarily from the Afghanistan-Pakistan theater and projects violence beyond it. It has been assessed as a major extra-regional terrorist threat and has conducted attacks in Afghanistan, Iran, Pakistan, and Russia. The group advances a transnational vision of “Khorasan” that explicitly encompasses parts of Central Asia and Iran, indicating ambitions that extend beyond its immediate operating environment. ISIS-K uses media and propaganda to recruit members and expand its influence. Its activity is associated with extremist mobilization and cross-border threat projection from the Afghanistan-centered militant ecosystem into neighboring regions. High-confidence reporting supports its role as an active terrorist actor with operational reach across multiple countries in South and Central Asia and into Russia. Based on the available facts here, its dominant motivation is terrorism. Specific cyber capabilities, ransomware activity, and detailed intrusion tradecraft are not supported by the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.