Skip to main content
Mallory

Houthis

Also known ashouthis

The Houthis, also known as Ansarallah, are an Iran-backed militant group in Yemen. The provided content describes them as an Iran-backed proxy or militia and, in some sources, as a terrorist organization or foreign terrorist organization. They control Yemen’s capital Sanaa and other territory. Based on the content, the Houthis have targeted commercial shipping in the Red Sea for months, contributing to regional instability and disruption of international commerce. They have also been linked to drone attacks on Saudi oil infrastructure, including the Abqaiq oil processing facility and the Khurais oil field, and to earlier attacks on the East-West Pipeline and the Shaybah oil field. The content further states that Houthi-linked financial infrastructure enabled missile attacks, drone strikes, and Red Sea disruptions. The content states that the Houthis have used cryptocurrency at increasing scale. TRM Labs documented their use of cryptocurrency to procure UAVs, drone components, and counter-drone systems via Chinese suppliers. OFAC sanctioned a network of financial and logistical facilitators tied to the Houthis on April 2, 2025, including eight cryptocurrency wallets used to support weapons procurement, commodities procurement, and sanctions evasion. Those wallets reportedly moved nearly $1 billion in illicit funds and interacted with wallets linked to previously sanctioned facilitator Sa’id al-Jamal. The content also notes OFAC’s December 2024 update to the designation of IRGC-connected Houthi financier Sa’id al-Jamal to include crypto wallets used for money laundering and illicit shipping of Iranian oil on behalf of the Houthis. The content also references broader facilitation and external support networks. It states that Russia-based actors and shipping entities facilitated arms movement, stolen Ukrainian grain shipments from Crimea to Yemen, and illicit payments supporting the Houthis. It also states that the Houthis have used mainstream exchanges as cash-out points and deposit addresses at sanctioned exchange Garantex. Chainalysis is cited as assessing that Iran-linked proxies and designated terrorist organizations including the Houthis have used cryptocurrency at increasingly greater scale. Additional activity attributed to or associated with the Houthis in the content includes statements calling for violence against U.S. assets and personnel in the Middle East; an opportunistic or transactional relationship with al-Shabab in Yemen; alleged cutting of submarine communication cables in the Red Sea in 2024; and GuardZoo surveillanceware tied to the Houthis. One article in the content also alleges that the Houthis benefited from Chinese-sourced weapons components, Russian satellite intelligence for maritime targeting, and diplomatic cover, and that they negotiated safe passage for Russian and Chinese vessels through the Red Sea, but these points are presented as allegations in the source material. Known alias in the provided content: Ansarallah.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Military
MITRE ATT&CK

Tradecraft

8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics9 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1592
Gather Victim Host Information
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1588
Obtain Capabilities
T1588.005
Exploits
TA0007
Discovery
1 technique
T1654
Log Enumeration
TA0009
Collection
1 technique
T1213
Data from Information Repositories
TA0040
Impact
2 techniques
T1489
Service Stop
T1498
Network Denial of Service
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping8

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.