Sonnenkrieg Division is a neo-Nazi accelerationist extremist group associated with the broader Siege-culture milieu inspired by James Mason’s ideology. It has been linked in public reporting to transnational online far-right ecosystems that overlap with Atomwaffen Division and The Base, and to communities active on platforms such as Telegram and Discord. The group is part of a violent white supremacist subculture that glorifies terrorism, promotes racist and anti-Semitic propaganda, and seeks societal destabilization through extremist violence. Sonnenkrieg Division has been identified as part of networks connected to killings and multiple prosecutions for attack conspiracies. Its presence has also been noted in persistent online radicalization spaces even after major platform moderation efforts, underscoring its role in digital extremist recruitment and propaganda dissemination. Within these ecosystems, Sonnenkrieg Division is associated with accelerationist narratives that valorize sabotage, terrorism, and the collapse of existing social and political order. The group is best understood as a violent far-right extremist actor rather than a conventional cyber threat actor. The available information supports its involvement in extremist networking, propaganda, and radicalization, but does not directly establish distinct cyber intrusion, ransomware, or financially motivated criminal operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Far-right extremist group referenced as part of online subcultures using Discord as a hub for extremist networking and radicalization.
Neo-Nazi Siege-culture-linked accelerationist network connected in the content to killings and conspiracies to commit attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.