Dark Storm Team is a pro-Palestinian hacktivist group active since late 2023, also referenced as Dark Storm, DarkStorm, dark_storm_team, and MRHELL112. The group is described as anti-Israel and as part of a broader pro-Iran-aligned or Axis-aligned hacktivist/proxy ecosystem, including being identified in reporting as part of a looser Iran-aligned proxy layer alongside groups such as 313 Team, DieNet, and Cyber Islamic Resistance. Reporting characterizes Dark Storm Team as occupying the criminal-adjacent edge of that ecosystem, where DDoS activity, ransomware narratives, and wartime propaganda blur. The group is primarily associated with large-scale distributed denial-of-service campaigns, website defacements, phishing campaigns, and claimed disruptive operations. Multiple sources in the content state that it has targeted NATO countries, Israel, and the United States, as well as entities in the Middle East more broadly. Specific targeting mentioned in the content includes Israeli government ministries and services, including the Ministry of Justice, Police, Education, and the Supreme Court; Israeli banking, including Union Bank of Israel; Israeli government ministry websites; and Western platforms. The content also states that Dark Storm Team monitored and targeted Israeli government ministries’ websites. Dark Storm Team has publicly claimed responsibility for several disruptive incidents, including the March 10, 2025 DDoS attack on X, and a DDoS attack that allegedly took BreachForums offline. The content notes that the X claim was made via Telegram and supported with Check Host screenshots, but also explicitly states that such self-attribution and screenshots do not prove responsibility. The group is also described as having claimed attacks on John F. Kennedy Airport, Los Angeles International Airport, Snapchat, and multiple Israeli government services. The content further states that Dark Storm Team has conducted ransomware attacks in addition to DDoS campaigns, and that it has advertised itself as hackers-for-hire despite its political messaging. Reporting compares its tactics to those of KillNet. During periods of regional escalation, Dark Storm Team is repeatedly listed among pro-Iranian or state-aligned hacktivist collectives claiming operations against government, financial, telecom, and critical infrastructure targets across Israel, Jordan, Saudi Arabia, Kuwait, Bahrain, and the United Arab Emirates. The content also records lower-volume public claim activity by Dark Storm Team during the Milano Cortina 2026 Winter Games period and in broader retaliatory hacktivist waves following the February 2026 U.S.-Israel campaign against Iran.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Criminal-adjacent actor in the pro-Iran ecosystem blending DDoS activity, ransomware narratives, and wartime propaganda.
Threat actor publicly claiming DDoS-related attacks against Italian targets during the Winter Games period.
State-aligned/pro-Iranian actor claiming retaliatory disruptive and destructive cyber operations against Israeli and Western organizations.
Hacktivist group named as participating in disruptive operations related to the conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.