The English Defence League (EDL) is a UK-based far-right street movement founded in 2009 and primarily known for anti-Muslim mobilization, protest activity, and extremist rhetoric centered on opposition to Islamism, multiculturalism, and immigration. It has been associated with nationalist and anti-Islam activism rather than with a coherent cyber threat program. The organization has been referenced by violent extremists as part of a broader ideological milieu, but it is distinct from clandestine terrorist cells and from self-styled revolutionary networks that advocate mass-casualty violence. Public reporting has long described the EDL as a loose movement with shifting local divisions, overlapping supporters, and links or affinities with other anti-Muslim and far-right currents in the United Kingdom. The alias EDL is commonly used. No high-confidence evidence in the supplied facts supports attributing cyber operations, ransomware activity, or defined intrusion capabilities to the group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Discussed as a democratic anti-Islamist movement distinct from KT. The content explicitly contrasts EDL with KT and says EDL condemns revolutionary conservative movements that use terror.
Discussed as a democratic anti-Islamist movement distinct from KT. The content explicitly contrasts EDL with KT and says EDL condemns revolutionary conservative movements that use terror.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.