The Muslim Brotherhood is a transnational Sunni Islamist movement founded in Egypt in 1928 by Hassan al-Banna. It is best known as a political-religious organization rather than a cyber threat actor. The movement has historically sought to shape society and governance according to its interpretation of Islam and has developed branches, affiliated organizations, and ideological offshoots across the Middle East and beyond. Prominent figures associated with the movement include Hassan al-Banna and Yusuf al-Qaradawi. Hamas is widely regarded as an offshoot of the Brotherhood, although it operates as a distinct organization. Available information in this record does not establish the Muslim Brotherhood as conducting cyber operations, malware campaigns, network intrusions, ransomware activity, or other clearly defined cyber threat activity. The material instead concerns political influence, ideological activity, organizational expansion, and public controversy surrounding Brotherhood branches and associated figures. References to alleged long-term strategic influence in Western countries appear in polemical and non-cyber contexts and do not provide high-confidence evidence of specific cyber capabilities or attack lifecycle behaviors. Because the supplied facts do not directly support attribution of cyber intrusions, espionage operations, financially motivated cybercrime, or destructive cyber activity to the Muslim Brotherhood, it should not be characterized here as a verified cyber threat actor. Any assessment beyond its identity as an Islamist movement originating in Egypt would be insufficiently supported by the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Discussed as an Islamist organization whose branches have been considered for designation, despite the article noting it renounced violence in the 1970s.
Described as pursuing restoration of the caliphate, building Islamist networks in Europe, infiltrating institutions, recruiting members, and leveraging democratic systems and civil society structures to expand influence.
Mentioned as an ideological and organizational influence behind expansion of political Islam and associated strategic activity in Europe.
Described as an Islamist organization whose leaders are portrayed in the text as seeking expansion of Islam into Europe and America.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.