Islamic State Khorasan Province (ISKP), also known as ISIS-K, is the Afghanistan-based affiliate of the Islamic State. It is a significant transnational jihadist threat with support networks and facilitation activity extending into Europe. ISKP claimed responsibility for the March 2024 Crocus City Hall mass-casualty attack in Moscow, Russia, and has encouraged attacks against Jewish communities and major sporting events. ISKP has developed into an important node in Islamic State cryptocurrency financing. Since at least 2022, it has raised and moved funds on public blockchains, relying heavily on stablecoins while also publicly soliciting privacy-coin donations through its Al-Azaim Foundation for Media propaganda outlet and its multilingual Voice of Khurasan publication. Its financing activity supports dispersed operatives, media operations, and the broader Islamic State network. Authorities have linked cryptocurrency transfers to ISKP-controlled wallets following the Crocus City Hall attack and have disrupted individuals involved in its media and cryptocurrency operations. The group’s fundraising infrastructure is decentralized across multiple subgroups and combines cryptocurrency with informal brokers and other financial facilitators. International law-enforcement operations have targeted ISKP-linked support networks, travel routes, and financing activity across Europe, including networks associated with Chechen and Central Asian individuals. ISKP is designated under United States counterterrorism sanctions, including sanctions targeting its cryptocurrency-financing infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted the March 2024 Crocus City Hall attack in Moscow and used cryptocurrency to finance part of the operation; also received crypto transfers from ISIS's Somalia-based al-Karrar office.
Used propaganda to incite attacks against Jewish communities in the context of the Gaza war.
A terrorist organization and ISIS affiliate using cryptocurrency financing infrastructure to raise, move, and conceal funds, including support for attacks and propaganda/media operations. The group relied heavily on USDT, later publicly solicited Monero donations through Voice of Khurasan, and maintained a decentralized fundraising network across multiple subgroups.
Jihadi terrorist organization whose support networks in Europe were targeted by a coordinated Europol-led operation focused on disrupting affiliated individuals, mapping travel routes, and advancing investigations across Europe, South America, and the United States.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.