Jama’at Nusrat al-Islam wal-Muslimin (JNIM), also rendered Jama’at Nasr al-Islam wal Muslimin, is an Al-Qaeda-affiliated jihadist coalition formed in 2017 and led by Iyad Ag Ghaly, a Malian national and former head of Ansar al-Dine. The group has expanded from its historical base in Mali into Burkina Faso and other parts of the Sahel through a flexible cross-border structure that combines military and religious authority. Senior figures identified in Burkina Faso include Amadou Kouffa, Jafar Dicko, Ousmane Dicko, and Abou Hanifa; affiliated components include Ansaroul Islam and Katiba Hanifa. JNIM has been linked to widespread violence against civilians in Burkina Faso since 2017 and was assessed as responsible for hundreds of civilian deaths between 2023 and 2025. Its operations have included unlawful killings, summary executions, retaliatory massacres, looting, destruction of civilian property, forced displacement, kidnappings, attacks on internally displaced persons, and the denial of humanitarian assistance through sieges of towns and villages. The group has used violence and coercion to establish or contest territorial control, punish communities accused of collaborating with state forces or local auxiliaries, and enforce displacement orders. It has also attacked military and police positions, humanitarian convoys, and civilian infrastructure, including communications and other essential services. In Burkina Faso, JNIM has demonstrated the ability to mount large-scale assaults involving substantial numbers of fighters, overrun security positions, free detainees, and then conduct post-capture reprisals against civilians. The group has also used improvised explosive devices on roads and contributed to prolonged blockades affecting large civilian populations. Human rights reporting has assessed that JNIM’s abuses in Burkina Faso amount to war crimes and crimes against humanity. JNIM’s dominant motivation is jihadist insurgency aligned with Al-Qaeda’s regional project, and its violence has been used to expand influence, undermine state control, and impose its authority across contested areas of the Sahel.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A jihadist group affiliated with Al-Qaeda that is expanding its influence in Burkina Faso, contesting or asserting influence over large portions of territory and carrying out attacks across the country.
Islamist armed group operating from Mali and expanded into Burkina Faso and other West African countries through affiliated armed groups; implicated in killings of civilians and other serious abuses documented in the report.
Islamist armed group conducting insurgent operations in Burkina Faso, including attacks on military and VDP positions, raids on villages, threats, forced taxation (zakat), recruitment pressure, sieges, and large-scale killings of civilians. The content also describes JNIM reprisals against civilians accused of collaborating with Burkinabè forces.
Islamist armed group and Al-Qaeda affiliate conducting insurgent operations in Burkina Faso and the wider Sahel. The content describes JNIM systematically targeting civilians, imposing sieges, using coercion to control territory, attacking humanitarian convoys, executing civilians, abducting women and girls, and retaliating against communities associated with VDPs or government forces.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.