Africa Corps is a Russian state-controlled expeditionary force operating across parts of Africa, widely regarded as the successor structure to the Wagner Group after the Kremlin moved to bring such overseas operations under tighter Ministry of Defense control. It supports Russian geopolitical influence through military assistance, regime protection, influence operations, and security partnerships, particularly in the Sahel. In Mali, Africa Corps has operated alongside the Malian Armed Forces in campaigns against Tuareg rebel formations and jihadist organizations, reflecting Moscow’s broader effort to displace Western influence and secure strategic access and political leverage in the region. The organization is associated with a continuation and institutionalization of Wagner’s intervention model rather than a clear break from it. Reported activity includes direct participation in combat operations, training and assistance to partner forces, support to counterinsurgency and counterterrorism missions, and involvement in information operations aligned with Russian state interests. Open-source reporting also links Africa Corps to the operational use of long-range one-way attack drones in Mali, giving Russian and partner forces an inexpensive strike capability at extended range, albeit with lower precision and heightened risk to civilians. Africa Corps has been tied to operations in Mali following the country’s political realignment toward Moscow after successive coups. Its presence forms part of a broader Russian strategy in the Sahel that combines military support, intelligence cooperation, disinformation, and transactional security relationships with ruling juntas. This model has been associated with support for regime consolidation as well as Russian access to local political and economic influence. The group has been repeatedly linked by credible reporting to serious human rights abuses in Mali, including torture, rape, forced disappearances, and extrajudicial killings during joint operations with local forces. These patterns mirror longstanding allegations against Wagner and have contributed to assessments that Africa Corps preserves the coercive and abusive characteristics of its predecessor. Analysts have also noted that such tactics can fuel insurgent recruitment, deepen communal grievances, and undermine long-term stabilization. Known aliases and related designations include africa_corps, and it is commonly described as Wagner’s successor in Africa. As a Russian government-run structure, Africa Corps should be understood as part of Moscow’s broader state power projection apparatus rather than as an independent private military actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian successor formation to Wagner operating in Mali alongside FAMa, assessed in the report as likely involved in deployment of Russian-manufactured Shahed-136/Geran type one-way attack drones for long-range strikes in northern Mali.
Russian Ministry of Defense-run force that replaced Wagner elements in the Sahel and continued combat involvement, training/support activities, and abusive counterterrorism operations.
Successor Russian proxy formation conducting influence operations and military special operations across Africa on behalf of Russia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.