Skip to main content
Mallory

Hamas

Also known ashamas

Hamas is a Palestinian militant and terrorist organization, described in the content as Iran-backed and as a designated terrorist organization/foreign terrorist organization. The content identifies the Al-Qassam Brigades as Hamas’s military wing. Hamas is described as having received long-term Iranian financial and military support, including money, weapons expertise, technology transfer, strategic mentorship, rocket blueprints, launcher expertise, training on propellants and explosives, and support related to surveillance drones, loitering munition components, and UAV assembly. The content states that Hamas fighters received training in Iran, Lebanon by Hezbollah, and at times in Syria, and that materiel was smuggled into Gaza through the Philadelphi Corridor. The content states that Hamas seeks the destruction of Israel, seized control of Gaza from the Palestinian Authority in 2007, and has fought multiple wars against Israel. It attributes to Hamas the October 7, 2023 attack on Israel, in which Hamas fighters entered Israel by land, air, and sea, fired thousands of rockets, attacked towns, military bases, and the Nova music festival, killed around 1,200 people, abducted about 150 to 250 people into Gaza, and threatened to execute hostages in response to Israeli airstrikes. The content further states that Hamas claimed to have moved hostages into an underground tunnel network. The content also describes Hamas activity beyond direct attacks. It states that Hamas and Palestinian Islamic Jihad praised the Hadera shootings as a “natural response” to the “summit of humiliation.” It reports that Hamas propaganda interrupted some private satellite-dish viewers of Israel’s Channel 2 broadcast in March 2016, replacing programming with Hebrew and Arabic threats and incitement. The content states that Hamas has used cryptocurrency, including activity involving wallets designated by Israel’s National Bureau for Counter Terror Financing, and that TRM Labs documented Hamas using cryptocurrency to procure UAVs, drone components, and counter-drone systems via Chinese suppliers. In Gaza-war reporting cited in the content, Hamas and PIJ military-wing operatives were used as categories in Israeli targeting and casualty databases, including the Lavender targeting system and an Aman database of named operatives. The content also notes that foreign terrorist organizations including Hamas issued media statements during the Israel-Iran conflict, some calling for violence against U.S. assets and personnel in the Middle East. Known alias in the provided content: Hamas.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Military
MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics13 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1590
Gather Victim Network Information
T1590.001
Domain Properties
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1588×2
Obtain Capabilities
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.003
Spearphishing via Service
TA0005
Stealth
1 technique
T1036
Masquerading
TA0009
Collection
1 technique
T1213
Data from Information Repositories
TA0011
Command and Control
1 technique
T1568
Dynamic Resolution
TA0010
Exfiltration
1 technique
T1537
Transfer Data to Cloud Account
TA0040
Impact
1 technique
T1499
Endpoint Denial of Service
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Hamas | Mallory