Dark Storm
Dark Storm Team is a pro-Palestinian, anti-Israel hacktivist group active since late 2023 (also referred to as Dark Storm, DarkStorm, dark_storm_team, and MRHELL112). The group is described as targeting governments and organizations perceived as supporting Israel, and has targeted entities in the Middle East, Israel, the United States, and NATO countries. Reported activity includes large-scale distributed denial-of-service (DDoS) campaigns, website defacements, phishing campaigns, and claimed ransomware attacks. Multiple sources in the content describe its tactics as similar to those of the Russia-linked KillNet group, and one source notes the group has advertised itself as hackers-for-hire despite its political messaging. Within the provided reporting, Dark Storm Team repeatedly claimed disruptive operations, including responsibility for the March 10, 2025 DDoS attack on X/Twitter, and a claim that it took BreachForums offline via DDoS. The content also places the group among actors conducting disruptive operations against Western and Israeli targets, including claimed attacks on Israeli government ministries and services such as the Ministry of Justice, Police, Education, the Supreme Court, and monitoring/targeting of Israeli government ministry websites. Additional mentions describe targeting of Israeli banking, including Union Bank of Israel, and attacks on major U.S. airports and Snapchat. In broader regional conflict reporting, Dark Storm Team is listed among pro-Iranian or pro-Palestinian hacktivist ecosystems involved in low-level DDoS attacks, website defacements, and phishing campaigns, and among groups claiming operations during escalations involving Israel, Iran, and Western-aligned targets. The content does not independently verify all public claims.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor publicly claiming DDoS-related attacks against Italian targets during the Winter Games period.
State-aligned/pro-Iranian actor claiming retaliatory disruptive and destructive cyber operations against Israeli and Western organizations.
Hacktivist group named as participating in disruptive operations related to the conflict.
Hacktivist group cited as participating in low-level DDoS attacks, website defacements, and phishing campaigns during the 2026 Iran war.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.