The Houthis, formally Ansar Allah, are an Iran-backed Yemeni rebel movement. They have conducted a maritime blockade campaign against Saudi-linked shipping in the Bab el-Mandeb and Red Sea corridor, declared effective in July 2026. The campaign has materially reduced commercial and tanker traffic and increased war-risk concerns for vessels associated with Saudi Arabia. Available reporting also indicates that certain Chinese-linked vessels have transited the blockade area without incident, consistent with a practical safe-passage arrangement or selective exemption. The group’s maritime activity constitutes a significant regional threat to freedom of navigation and commercial shipping.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iran-backed Yemeni rebel group identified as a continuing regional-security concern in the context of the Iran war.
Conducting a maritime blockade campaign affecting shipping through Bab el-Mandeb and the Red Sea, while some Chinese-linked vessels reportedly transit unharmed.
Enforcing a blockade and selective access regime in the Bab el-Mandeb/Red Sea corridor, targeting Saudi-linked shipping while reportedly exempting or granting safe passage to Chinese vessels.
Enforcing a blockade against Saudi-linked shipping in the Red Sea/Bab el-Mandeb, driving reduced tanker traffic, increased dark activity, and apparent exemptions for Chinese- and Russian-linked vessels.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.