JNIM, short for Jamaat Nasr al-Islam wal-Muslimin, is an al-Qaeda-affiliated militant group active in the Sahel. It operates primarily in Mali, Burkina Faso, and Niger, and has also been linked to activity in Togo. The group has coordinated attacks with the Azawad Liberation Front and is part of the broader jihadist insurgency challenging state control across the central Sahel. JNIM has demonstrated adaptation to modern battlefield technologies and irregular warfare conditions. Reported activity includes more than a dozen coordinated drone operations between September 2023 and April 2025 across Burkina Faso, Mali, and Togo, indicating an ability to integrate unmanned systems into insurgent operations. The group has also exploited the political and humanitarian effects of state military actions; after a 2024 military strike in Burkina Faso that killed dozens of civilians, JNIM reportedly organized rescue operations and deployed medical personnel, reflecting a strategy of leveraging civilian harm for influence and recruitment. The group’s operational profile is consistent with an insurgent organization focused on coordinated attacks, battlefield adaptation, and expansion in weakly governed areas rather than financially motivated cybercrime or ransomware activity. Known naming variants include Jamaat Nasr al-Islam wal-Muslimin and Jamaat Nasr al-Islam wal-Muslimin (JNIM).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.