HAYI is a little-understood pro-Iranian proxy or aligned group that emerged in reporting around suspected attacks and intimidation activity in Europe in 2026. It has been publicly associated with claims of responsibility for violent or disruptive incidents targeting Jewish, Israeli, or other politically symbolic targets, but the credibility of at least some of those claims has been questioned by investigators and researchers. Available reporting indicates that HAYI may function partly as a propaganda or attribution vehicle within a broader ecosystem of Iran-aligned actors rather than as a consistently verified operational organization. HAYI has been discussed in connection with suspected Iran-linked gray zone activity in Europe, including deniable violence and sabotage conducted below the threshold of open interstate conflict. Such activity has been assessed more broadly as relying on proxies, criminal facilitators, or hired local operatives to obscure direct state responsibility while intimidating targets and imposing political costs. In that context, HAYI has been described as pro-Iranian and as a possible proxy actor, with some expert commentary assessing Iran as the most likely state sponsor if foreign backing is confirmed. However, attribution remains uncertain, and some incidents claimed by HAYI may have been opportunistic claims made after the fact. The group has also appeared in European counterterrorism and online-content disruption activity as an aligned entity within the wider Iranian influence and proxy landscape. Authorities tracing and removing online propaganda linked to the Islamic Revolutionary Guard Corps identified HAYI alongside other Iran-aligned organizations such as Hezbollah, Ansar Allah, Hamas, and Palestinian Islamic Jihad. This suggests at minimum a propaganda, messaging, or ideological alignment with the broader IRGC-linked ecosystem, though the precise command-and-control relationship is not publicly established. High-confidence public information on HAYI’s structure, leadership, membership, operational history, and tradecraft remains limited. No well-corroborated sub-groups or alternate aliases are currently available beyond the name HAYI itself. The most defensible characterization is that HAYI is an emerging, pro-Iranian, possibly proxy-linked actor associated with claims around suspected attacks in Europe and with the online media environment of Iran-aligned militant and extremist entities, but whose exact operational role and degree of Iranian state direction remain unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a new Iranian-aligned proxy group operating in Europe and recruiting teenagers via Snapchat for a bombing attempt in Paris.
Referenced as an aligned entity producing statements and videos disseminated online in support of IRGC-linked propaganda ecosystems.
Claimed responsibility for an arson-style attack on an Israeli restaurant in Munich, though the claim is described as potentially not credible and possibly opportunistic.
Claimed responsibility for a series of suspected attacks in Europe; described as a pro-Iranian group and potentially supported by a foreign state.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.