Cyber Jihad Movement (CJM) is a pro-Iran, resistance-aligned hacktivist and propaganda actor operating within a broader transnational ecosystem of loosely coordinated cyber militias, proxy brands, and influence networks. Its primary role is not distinguished by advanced intrusion tradecraft, but by recruitment, ideological mobilization, and amplification of disruptive cyber campaigns conducted by allied actors. CJM has been associated with public calls for “global cyber jihad” against the United States, Israel, and allied governments, helping expand participation and narrative reach across online platforms, especially Telegram-based coordination spaces. CJM functions as part of a wider coalition that includes Iran-aligned hacktivist brands, cyber militias, and state-adjacent influence nodes. Within that ecosystem, CJM contributes attack-volume amplification, rhetoric, target-list circulation, and claims promotion rather than uniquely sophisticated operations. The broader coalition commonly relies on low- to moderate-sophistication methods such as distributed denial-of-service activity, website defacements, credential reuse, recycled breach material, public leak claims, intimidation messaging, and propaganda dissemination. CJM’s role is best understood as an ecosystem enabler that helps mobilize supporters, reinforce psychological pressure, and magnify the perceived scale and political impact of campaigns carried out by aligned groups. CJM has been named alongside actors such as Handala, 313 Team, Dark Storm Team, Fatimiyoun/FAD Team, Keymous+, DieNet, MONARCH, Killnet, and Cyber Islamic Resistance as part of a broad anti-Western and anti-Israeli cyber front. This network is characterized by rapid mobilization during geopolitical crises, shared target selection, mutual amplification of claims, and deniable alignment with Iranian strategic interests. CJM’s dominant function in that environment is influence-oriented cyber mobilization in support of disruptive and coercive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extends the coalition’s reach by recruiting and amplifying propaganda, including public calls for global cyber jihad against the U.S., Israel, and allied governments.
Hacktivist actor contributing attack volume, rhetoric, target lists, and claims amplification within the pro-Iran ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.