The English Defence League (EDL) is a UK-based far-right anti-Muslim street movement founded in 2009. It is best known for public demonstrations, confrontational activism, and anti-Islam rhetoric rather than for operating as a conventional cyber threat actor. The movement has been associated with broader anti-immigration and anti-multicultural extremist milieus in Europe, and it has inspired or been referenced by aligned groups and local offshoots in other countries, including the Norwegian Defence League. In extremist discourse surrounding the 2011 Norway attacks, the EDL was discussed as an ideological reference point but contrasted with more explicitly terrorist and revolutionary frameworks such as the self-styled Knights Templar concept. High-confidence reporting supports describing the EDL as a far-right extremist movement originating in the United Kingdom; however, the available facts here do not establish that the EDL itself conducted cyber operations, ransomware activity, or the attack lifecycle behaviors typically tracked for intrusion sets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named movement contrasted with KT. The content describes EDL as a democratic anti-Islam movement that rejects terrorism and condemns revolutionary conservative violence.
Referenced as a named movement contrasted with KT. The content describes EDL as a democratic anti-Islam movement that rejects terrorism and condemns revolutionary conservative violence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.