The Nordic Resistance Movement (NRM) is a pan-Nordic extremist organization founded in Sweden in 1997. It advocates for a Nordic ethnostate encompassing Sweden, Norway, Denmark, Finland, and Iceland, and is associated with white supremacist and antisemitic ideology. In June 2024, the United States designated the group as a Specially Designated Global Terrorist entity. Finland banned the organization in 2020 on the grounds that its activities were significantly contrary to law. As of March 2024, Tor Fredrik Vejdeland was identified as the group’s leader. NRM has maintained a sustained fundraising apparatus centered on cryptocurrency donations for nearly a decade, including activity across multiple Nordic branches. The organization publicly promoted cryptocurrency contributions after losing access to traditional banking services, and it accepted a range of digital assets. Observed financial activity indicates long-term use of crypto wallets to receive donations and subsequently move funds, primarily to exchanges, consistent with cash-out behavior. This demonstrates an operational capability for crypto-enabled fundraising and movement of funds across affiliated entities. Known associated individuals sanctioned in connection with the organization include Leif Robert Eklund, Pär Öberg, and Tor Fredrik Vejdeland. High-confidence reporting in this context supports the group’s role as an extremist and terrorist organization with a primary emphasis on ideological activity and financing rather than a documented cyber intrusion program.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.