The Islamic State of Iraq and the Levant (ISIL), also widely known as ISIS, is a Sunni jihadist terrorist organization that emerged from al-Qaeda in Iraq and developed into a structured insurgent and proto-state actor operating primarily in Iraq and Syria. The group pursued territorial control, state-building, and sectarian governance, and became known for combining conventional insurgent warfare with terrorism, propaganda, and diversified financing. ISIL documented its military activity through detailed annual reporting that quantified bombings, assassinations, suicide operations, checkpoints, territorial seizures, and prisoner releases, reflecting a bureaucratic and operationally organized structure. Its campaigns heavily targeted Iraq, especially Nineveh province and Mosul, while also expanding across parts of Syria including areas around Aleppo and Deir Ezzor. The organization financed itself through extortion, kidnappings, oil smuggling, looting, and support from private jihadi donor networks in the Gulf. In the cyber domain, ISIL-linked facilitators have used online infrastructure, social media, and cryptocurrency-enabled schemes to raise and move funds. One documented case involved an ISIL facilitator associated with select hacking operations who used an online fraud scheme during the COVID-19 period to generate revenue through the sale of fake protective equipment. The group has also demonstrated sophisticated use of social media for propaganda, recruitment, and outreach, including attracting foreign fighters. Known aliases include ISIS and ISIL. The organization’s dominant activity profile is terrorism and insurgency rather than financially motivated cybercrime, although it has used cyber-enabled fraud and online fundraising in support of its broader militant objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using cyber-enabled fraud, including a fake PPE sales website and related social media pages, to generate funds for terrorist operations.
Militant organization conducting large-scale violent operations in Iraq and Syria, including bombings, assassinations, IED attacks, suicide missions, territorial seizures, extortion, kidnappings, oil smuggling, and coordinated propaganda/social media campaigns to support state-building ambitions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.