United Cyber Caliphate (UCC) was an Islamic State-linked pro-ISIS hacking and propaganda collective that emerged as an umbrella for multiple supporter cyber groups, including Ghost Caliphate Section, Sons Caliphate Army, and Kalachnikv E-Security Team. It is associated with the broader evolution of Islamic State online operations following the Islamic State Hacking Division and Islamic Cyber Army. UCC pledged allegiance to ISIS and combined cyber-enabled intimidation, propaganda dissemination, recruitment, and support for hacking activity against perceived enemies of the group. The group is known for publishing so-called kill lists containing personal information of thousands of individuals and explicitly urging lone-actor violence against those named. Reported targets included U.S. military personnel, U.S. government employees, and civilians in the New York City area. UCC also used social media and encrypted communications to spread extremist propaganda, recruit supporters, coordinate activity, and publicize completed intrusions. Members and associates were alleged to assist hacking operations by identifying website targets, relaying them to hackers, and amplifying the results for propaganda purposes. UCC activity included cyber intrusions and the use of stolen personal data from hacked sources to support intimidation campaigns and incitement to violence. The organization also recruited foreign supporters, including minors, into both media and hacking roles, and promoted violent attacks as models for further action. Its operations were primarily aligned with terrorist propaganda and coercive influence rather than financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Islamic State-linked hacking group that posted online kill lists containing personal information of thousands of Americans and urged followers to murder listed individuals in lone-wolf attacks.
Islamic State-aligned hacking umbrella organization involved in propaganda dissemination, recruitment, website hacking coordination, and publication of kill lists containing personal information of thousands of Americans.
Pro-ISIS cyber activity group that pledged allegiance to ISIS, conducted online attacks and cyber intrusions against Americans, disseminated ISIS propaganda and kill lists, and recruited individuals to support hacking and extremist media operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.