al-Shabab is a Somalia-based Islamist militant and insurgent organization aligned with al-Qaeda. It has been one of the most significant violent extremist actors in the Horn of Africa for more than two decades and is primarily engaged in insurgency and terrorism against the Somali government and its partners, while also conducting attacks in neighboring Kenya. The group is widely associated with sustained violence in Somalia and has been the target of repeated Somali and U.S. counterterrorism operations, including drone strikes against senior leaders. Operationally, al-Shabab combines guerrilla warfare, terrorist attacks, intimidation, propaganda, and extortion. It has used digital platforms, including WhatsApp, for propaganda, extortion, and intimidation activities. Reporting also indicates the group has adapted its fieldcraft to evade aerial surveillance and strikes by shifting away from more conspicuous vehicle movement toward lower-signature transportation methods. It has demonstrated the ability to threaten military installations, exploit cross-border operating space, and sustain pressure on state security forces and civilian populations. The group has targeted Somali state institutions and security forces and has also attacked Kenyan interests, including high-profile mass-casualty operations. It is assessed as part of the broader al-Qaeda network and has been described as a powerful insurgent force in Somalia. Available reporting also notes an opportunistic or transactional relationship with the Houthis in Yemen. Based on the supplied facts, al-Shabab is best characterized as a jihadist insurgent and terrorist actor whose dominant objective is ideological and political violence rather than financially motivated cybercrime, even though it uses extortion and digital communications in support of its operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Militant group cited as using WhatsApp and related groups for extortion, intimidation, and propaganda in Somalia.
Militant group cited as a counterterrorism target in Africa, particularly in Somalia.
Somali Islamist militant group discussed as a target of drone strikes and as an actor adapting its tactics to evade aerial surveillance and strikes.
Militant insurgent group operating in Somalia and Kenya, conducting terrorist attacks, using IEDs, and threatening regional security while maintaining links to al-Qaeda.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.