Mr. Hamza Ecosystem is a Moroccan-origin cybercrime and hacktivist support network centered on botnet development, sales, and operational enablement for aligned groups in the pro-Iran “Resistance Axis” milieu. Rather than being primarily known for standalone espionage or destructive intrusions, it functions as a commercial and coordination enabler that supplies botnet capability and infrastructure support to affiliated actors involved in disruptive campaigns. The ecosystem has been associated with providing multiple botnet and command-and-control offerings to groups such as Hunt3r Kill3rs, EvilMorocco, and the Moroccan Black Cyber Army. Its role is closely tied to distributed denial-of-service operations and broader disruption activity conducted by partner collectives. In this capacity, it serves as a force multiplier for hacktivist-style campaigns that emphasize service disruption, propaganda amplification, and coalition support rather than covert long-term access. Mr. Hamza Ecosystem sits within a broader network of pro-Palestinian and pro-Iran-aligned cyber actors that includes groups participating in coordinated anti-Israel and regional operations. Its documented function is that of an enabling node for botnet-backed attacks and allied offensive activity, especially where scalable disruption and operational support are required. High-confidence reporting supports Moroccan origin and a primary role in DDoS facilitation and associated cybercrime support services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.