Quwat Dhu al-Fiqar is an Iran-aligned Iraqi Shia militant faction within the broader "axis of resistance" ecosystem. It has been observed in the online propaganda distribution network that amplifies claims of attacks attributed to Harakat Ashab al-Yamin al-Islamiya (Hayi), including messaging about alleged attacks on Jewish and Israeli-linked targets in Europe. Reporting links channels supportive of Quwat Dhu al-Fiqar to dissemination of Hayi propaganda, indicating at minimum an information-support or amplification role within a wider pro-Iran militant media environment. The available information directly supports Quwat Dhu al-Fiqar’s association with propaganda and influence activity tied to militant messaging, but does not establish with high confidence that the group itself executed the cited attacks. The broader network in which it appears has been associated with antisemitic and anti-Israel narratives and with circulation of attack claims targeting Jewish sites in countries including the United Kingdom, Belgium, the Netherlands, and Greece. High-confidence evidence in the available material is insufficient to attribute specific operational capabilities, victim sectors, or attack execution directly to Quwat Dhu al-Fiqar beyond propaganda support and alignment with Iran-backed militant ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.