HAYI is a pro-Iranian proxy group that emerged in the context of suspected Iran-linked gray-zone activity in Europe in 2026. It has been publicly associated with claims of responsibility for suspected attacks in Europe, including incidents directed at Jewish and Israeli-linked targets, but the credibility of at least some of those claims has been questioned by investigators and subject-matter experts. Available reporting indicates that HAYI may function within a broader ecosystem of Iranian-aligned entities and propaganda networks rather than as a clearly delineated, independently attributable operational organization. HAYI has been referenced alongside other Iranian-aligned groups in European counterterrorism activity targeting online propaganda, recruitment, and support infrastructure linked to the Islamic Revolutionary Guard Corps. This association suggests alignment with Iranian influence and support networks, but direct command-and-control relationships are not established at high confidence. Expert assessments cited in connection with suspected attacks in Europe indicate strong indications of foreign-state backing, with Iran considered the most likely sponsor, though attribution remains partly speculative. Operationally, HAYI has been linked to suspected targeted violence and intimidation activity in Europe. Reporting on suspected Iran-linked operations in Europe indicates the possible use of proxies, hired criminals, and deniable methods to obscure state involvement while pressuring or intimidating Jewish and Israeli targets. Because some claimed operations may have been opportunistic or falsely claimed after the fact, HAYI’s independently verified attack record remains limited. The group is best characterized as a suspected pro-Iranian proxy or aligned entity involved in deniable influence and violence-linked activity in Europe, with likely relevance to Iranian covert action and intimidation campaigns rather than conventional cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a new Iranian-aligned proxy group operating in Europe and recruiting teenagers via Snapchat for a bombing attempt in Paris.
Referenced as an aligned entity producing statements and videos disseminated online in support of IRGC-linked propaganda ecosystems.
Claimed responsibility for an arson-style attack on an Israeli restaurant in Munich, though the claim is described as potentially not credible and possibly opportunistic.
Claimed responsibility for a series of suspected attacks in Europe; described as a pro-Iranian group and potentially supported by a foreign state.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.