Terrorgram, also referred to as the Terrorgram Collective, is a decentralized transnational extremist network centered on Telegram channels that promotes militant accelerationism, neo-Nazi ideology, and violent white supremacist propaganda. It functions as a loose online milieu rather than a conventional hierarchical organization, using propaganda, glorification of previous attackers, and dissemination of guidance intended to encourage further acts of terrorism and extremist violence. The network has been linked to the production and distribution of far-right extremist propaganda and to the sharing of manuals and operational guidance for terrorist attacks, including material discussing attacks on critical infrastructure. Members and supporters have used multiple Telegram profiles and channels to spread ideological content, celebrate perpetrators as “saints,” and provide instructional material intended to radicalize and mobilize followers toward offline violence. Authorities in multiple countries have treated Terrorgram as a serious cross-border terrorist threat. It has been designated as a terrorist organization or terrorist entity in the United States, Canada, the United Kingdom, and Australia. Law-enforcement and counterterrorism investigations have identified linked individuals across Europe and North America, including convictions in Canada and Denmark for terrorism-related offenses tied to producing and disseminating propaganda and providing guidance in support of the network. Investigative work has emphasized Terrorgram’s transnational reach, decentralized structure, and role in inspiring terrorist attacks. Terrorgram is best characterized as an extreme-right terrorist and propaganda ecosystem whose dominant purpose is ideological radicalization and incitement to violence rather than financially motivated cybercrime or ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loose network of extreme-right terrorist channels that glorifies prior attackers and encourages further violence, including antisemitic targeting.
A decentralised online extremist network on Telegram promoting militant accelerationism and neo-Nazi ideology, publishing propaganda and sharing manuals for terrorist attacks including against critical infrastructure.
An online extremist network promoting violent white supremacist ideology and propaganda, with content linked to inspiring multiple terrorist attacks. Europol mapped the network, identified linked individuals across Europe and beyond, and supported international investigations.
Telegram-based extremist community designated as a terrorist organization; primarily focused on recruitment/incitement rather than malware operations (as described here).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.