Kata'ib Hezbollah (KH) is an Iran-backed Iraqi Shia militia and proxy organization aligned with the Islamic Revolutionary Guard Corps (IRGC). It is widely recognized as part of Iran’s regional proxy network and has been linked to external operations beyond Iraq. Known aliases include Kata’ib Hezbollah and Kataib Hezbollah. Reporting also associates KH with an external-operations-focused persona or sub-brand called the Islamic Movement of the Companions of the Right (IMCR), also known as Ashab al-Yamin and HAYI. The group has been implicated in plotting and orchestrating attacks against Jewish and Israeli-associated targets and in supporting antisemitic threat activity. Allegations in 2026 tied a senior KH operative to attacks in Europe and the United States conducted on behalf of the IRGC. Separate reporting stated that a KH commander linked to IMCR allegedly attempted to recruit an individual in the United States to attack multiple synagogues in exchange for cryptocurrency payment, indicating use of proxies and financially motivated intermediaries for initial access to attack operations. Available information in this context supports KH involvement in externally directed physical threat activity, particularly against Jewish community targets in the United States and Europe, and places the organization within the broader Iran-aligned “axis of resistance” ecosystem. Its observed behavior here is most consistent with proxy-enabled initial access, operational planning, and post-compromise orchestration in support of Iranian state objectives. The dominant motivation reflected in this context is espionage-aligned state proxy activity rather than purely independent militia action.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked proxy whose commander allegedly sought to recruit a purported US-based criminal operative to attack synagogues in the US.
A pro-Iranian Iraqi militia whose alleged senior operative was charged with orchestrating HAYI-claimed attacks on behalf of the IRGC.
An Iran-backed Iraqi faction referenced in connection with Telegram channels that amplified Hayi attack claims and propaganda.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.