Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇮🇱 IL

Unit 8200

Also known asUnit 8200

Unit 8200 is an elite cyber and signals intelligence group within the Israel Defense Forces. The provided content describes it as conducting large-scale surveillance of Palestinians in Gaza and the West Bank, including a cloud-based system that reportedly became operational in 2022 and enabled storage and replay of millions of mobile phone calls per day. According to the cited reporting, Unit 8200 used Microsoft Azure for this system after seeking additional storage and compute capacity, and sources alleged the resulting intelligence was used to support military operations, including researching or identifying targets for airstrikes, as well as detention, blackmail, and post hoc justification of killings. The content also states that under commander Yossi Sariel, Unit 8200 pursued a broader mass-surveillance strategy described by a source as 'tracking everyone, all the time,' and developed an AI-assisted text-message analysis system called 'noisy message' that scans Palestinian text messages and assigns risk ratings based on suspicious terms. The content further notes speculation in multiple media reports and by experts that Israel, through Unit 8200, was behind Stuxnet as part of the broader U.S.-Israeli operation commonly associated with Operation Olympic Games, though this is presented as speculation rather than confirmed attribution in the provided material. Known alias in the content: unit_8200.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Media & Entertainment

Where they target

Geographies tied to known operations.

  • 🇵🇸 Palestinian Territories

Where they're from

Attributed origin per open-source reporting.

  • IL
MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics10 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1590
Gather Victim Network Information
TA0006
Credential Access
1 technique
T1606
Forge Web Credentials
T1606.001
Web Cookies
TA0009
Collection
4 techniques
T1119×2
Automated Collection
T1123
Audio Capture
T1125
Video Capture
T1213×2
Data from Information Repositories
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Unit 8200 | Mallory