The Islamic State Hacking Division was an Islamic State-linked cyber unit active by 2014 and associated with the group’s broader online propaganda, recruitment, and cyber-enabled intimidation efforts. It was reportedly led by Junaid Hussain, a British-born Pakistani Islamic State operative, and later evolved through rebranding and consolidation into the Islamic Cyber Army and then the United Cyber Caliphate umbrella organization. Associated sub-groups included the Ghost Caliphate Section, Sons Caliphate Army, and Kalachnikv E-Security Team. The group and its successor structures were tied to hacking-related activity in support of the Islamic State’s extremist agenda, including theft of personal information, dissemination of propaganda, recruitment of supporters through encrypted messaging platforms, and publication of kill lists intended to incite lone-actor violence. Reported operations included stealing personal data from U.S. military and government personnel and later using hacked data from an American business to compile and release a larger list of U.S. persons. Members and associates were also alleged to support attack operations by identifying website targets, relaying them to hackers, and publicizing completed intrusions. Operationally, the Islamic State Hacking Division and successor entities combined cyber activity with psychological operations and influence messaging rather than demonstrating the sophistication typical of advanced state-sponsored intrusion sets. Their activities centered on initial access to obtain personal information, exfiltration, propaganda dissemination, recruitment, and post-compromise publicity. The actor’s dominant purpose was to support terrorist objectives through intimidation, incitement, and online mobilization rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Islamic State hacking branch that stole sensitive personal information of 1,351 U.S. service members and government employees from databases.
Islamic State Hacking Division
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.