Nightmare is a hacktivist group referenced in reporting as a pro-Palestinian actor that conducted disruptive operations against Israeli targets, including the websites of the Tel Aviv Stock Exchange and El Al airlines. The group also appears in a 2016 Hackforums thread in which Anna-Senpai contributed to a discussion started by a group calling itself Nightmare. Separately, content associates a threat actor named Florence with the Nightmare group; Florence advertised the sale of root-level remote code execution and shell access to a Linux-based firewall protecting the Botswana Government Health Portal. That listing described access that could enable arbitrary command execution, firewall rule modification, traffic interception, persistence, and lateral movement into internal government healthcare systems. The content maps the claimed access to ATT&CK techniques T1190 (Exploit Public-Facing Application), T1059.004 (Unix Shell), T1040 (Network Sniffing), and T1562.004 (Disable or Modify Firewall). Known associated alias from the content: Florence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the sale of root-level RCE and shell access to a Linux-based firewall protecting the Botswana Government Health Portal, enabling potential traffic interception, defense evasion, and lateral movement into government healthcare infrastructure.
Hackforums clique referenced as a hacker group to which Anna-Senpai applied for membership; no operational activity beyond that is described in the content.
Pro-Palestinian hacktivist group conducting disruptive attacks against Israeli financial and transportation targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.