Harakat Ashab al-Yamin al-Islamia, also referred to as Ashab al-Yamin and HAYI, is a previously unknown militant brand that emerged in 2026 claiming responsibility for a series of low-casualty attacks against Jewish and Israeli- or U.S.-linked targets in Europe, including incidents in Belgium, the Netherlands, and the United Kingdom. Available reporting indicates the entity is likely better understood as a front identity, façade, or media construct embedded in a broader Iranian-aligned Telegram ecosystem rather than a mature, clearly delineated standalone organization. Multiple assessments have linked its dissemination patterns, claim activity, and supporting media to channels associated with pro-Iranian Iraqi militias and the wider Islamic Resistance messaging environment, with some analyses identifying indicators consistent with involvement by networks aligned with Iran’s Islamic Revolutionary Guard Corps, particularly the Quds Force. The group’s observable presence has been concentrated on Telegram, where it issued attack claims, propaganda, and geopolitical commentary in Arabic. Its digital footprint has been fragmented and unstable, with limited persistent original infrastructure, inconsistent branding, misspellings in logos and statements, and heavy reliance on secondary amplifiers and affiliated channels to preserve and redistribute content. Attack videos and claims were circulated rapidly through pro-Iranian channels, including outlets associated with militia-linked propaganda ecosystems, and some reposted media carried branding tied to Iranian-aligned messaging networks. This pattern, together with the absence of a durable leadership presence or coherent organizational messaging, supports the assessment that Harakat Ashab al-Yamin al-Islamia may function primarily as a deniable claim vehicle for attacks conducted by loosely connected operatives or locally recruited proxies. The attacks attributed to the group have primarily targeted Jewish community sites and symbols, including synagogues, a Jewish school, and Jewish community-associated vehicles, alongside other targets framed as American or Zionist interests. The operational pattern described in reporting emphasizes nighttime or early-morning attacks designed to intimidate and create insecurity while limiting casualties, a profile assessed as consistent with hybrid warfare and coercive signaling rather than mass-casualty terrorism. Several analyses further assess that perpetrators were likely recruited locally, including youths or individuals on the margins of criminal milieus, echoing broader Iranian use of disposable agents and criminal intermediaries in Europe. Harakat Ashab al-Yamin al-Islamia has also been associated with threat messaging against Western, Israeli, and Jewish interests more broadly, and with propaganda overlapping militia, resistance, and geopolitical narratives aligned with Iranian interests. Some claimed incidents outside the core set of verified attacks have been assessed as unsupported or likely disinformation, reinforcing doubts about the group’s independent operational credibility. Overall, the actor is best characterized as an Iranian-aligned, likely proxy or front-linked threat identity used to claim and amplify intimidation attacks in Europe, especially against Jewish targets, with a dominant role in propaganda dissemination and psychological impact rather than demonstrated large-scale militant capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed a series of attacks in Europe since early March 2026, with most of the claimed attacks targeting Jewish institutions.
Emerging group claiming attacks across Europe via Telegram; assessed in the content as likely a front identity or visible node within a broader Iranian-aligned/"Islamic Resistance" media and amplification ecosystem rather than a clearly centralized standalone organization.
Claimed a series of explosive and arson attacks targeting Jewish and Israeli-linked sites in Belgium, the Netherlands, and the UK; the content assesses the group may be a façade or cover mechanism for Iranian-backed hybrid operations rather than a genuine independent terrorist organization.
An unknown group that claimed responsibility for firebomb attacks against Jewish and American targets in Belgium and the Netherlands; the report assesses its messaging and digital footprint as likely linked to Iranian proxy or IRGC-connected influence operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.