Ansar Allah, commonly known as the Houthis, is a Yemeni militant movement and Iranian-aligned proxy actor that emerged in northern Yemen in the 1990s and is led by Abdul-Malik al-Houthi. The group has developed from an insurgent movement into a major armed actor controlling significant territory in Yemen, including Sana'a since 2014. High-confidence reporting links its military development to sustained external support from Iran, particularly the Islamic Revolutionary Guard Corps–Quds Force, including weapons smuggling and the transfer of weapon components. Hezbollah advisors have also been associated with Houthi training. Ansar Allah has employed missiles and drones in attacks against commercial shipping and Western naval vessels in and around the Red Sea, demonstrating capabilities associated with long-range strike operations and maritime coercion. The group is also part of a broader network of Iranian-aligned entities whose media and propaganda ecosystems have been monitored alongside those of the IRGC, Hezbollah, Hamas, Palestinian Islamic Jihad, and other aligned organizations. This reflects its role not only as an armed proxy but also as a participant in coordinated messaging and support infrastructure. The actor’s activities indicate capabilities in initial access to conflict environments through armed operations, reconnaissance and propaganda support functions, and exfiltration or cyber-enabled behaviors are not established here at high confidence. The dominant pattern supported at high confidence is militant and proxy warfare in service of regional confrontation aligned with Iranian strategic interests. Known aliases include Ansar Allah and the Houthis.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an aligned entity producing statements and videos disseminated online in support of IRGC-linked propaganda ecosystems.
Iran-backed Yemeni militant group using missiles, drones, and maritime attacks against commercial shipping, Western naval vessels, Saudi Arabia, and Israel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.