Nightmare is a hacktivist threat actor name that has been associated with politically motivated disruptive activity and, more recently, with criminal access-brokering behavior. The group has been publicly linked to pro-Palestinian operations, including distributed denial-of-service activity against Israeli organizations such as the Tel Aviv Stock Exchange and El Al. Separate reporting also associates a member or affiliate using the name Florence with the sale of root-level remote code execution and shell access to a Linux-based firewall protecting a Botswana government health portal, indicating that the Nightmare label has been used in contexts beyond pure website disruption. Observed behavior attributed to Nightmare includes denial-of-service attacks, exploitation of public-facing systems, sale of initial access, shell-level post-compromise access, and activity consistent with persistence, lateral movement, defense evasion, and network traffic interception once privileged perimeter access is obtained. The Botswana-related activity suggests interest in government and healthcare environments and demonstrates operational overlap with intrusion-enablement tradecraft rather than solely ideological disruption. At high confidence, Nightmare should be characterized as a hacktivist-branded actor with demonstrated disruptive operations against Israeli targets and at least one reported case involving the monetization of privileged access into a government healthcare environment. The available information does not support a confident attribution to any state sponsor or a specific country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the sale of root-level RCE and shell access to a Linux-based firewall protecting the Botswana Government Health Portal, enabling potential traffic interception, defense evasion, and lateral movement into government healthcare infrastructure.
Hackforums clique referenced as a hacker group to which Anna-Senpai applied for membership; no operational activity beyond that is described in the content.
Pro-Palestinian hacktivist group conducting disruptive attacks against Israeli financial and transportation targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.