Antifascistisk Aktion (AFA) is a militant far-left anti-fascist network active in Sweden. It is associated with direct-action activism and has been publicly linked to physical attacks against ideological opponents, including anti-immigration and right-wing activists. Reporting has also associated the group with doxxing-style exposure of targets by publishing identifying personal details, indicating an intimidation component alongside street-level violence. AFA has been cited in connection with assaults around political events and public demonstrations, including incidents tied to Stockholm Pride and attacks on Sweden Democrats and related circles. The group’s activity profile is consistent with politically motivated extremist violence and harassment rather than financially motivated cybercrime. Based on the available facts, its dominant motivation is hacktivism. High-confidence evidence in the available material supports physical intimidation, target identification, and harassment, but provides limited substantiated detail on cyber-specific tradecraft beyond exposure of personal information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as a militant anti-fascist/extreme-left network conducting physical attacks, harassment, vandalism, and disruption of political events and demonstrations in Sweden and Germany.
Described as a militant anti-fascist/extreme-left network conducting physical attacks, harassment, vandalism, and disruption of political events and demonstrations in Sweden and Germany.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.