Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors
🇮🇷 IR

Harakat Ashab al-Yamin al-Islamia

Also known asharakat_ashab_al_yamin_al_islamia

Harakat Ashab al-Yamin al-Islamia (HAYI), also referred to as Ashab al-Yamin, is a previously unknown group that emerged in 2026 claiming responsibility for a series of low-casualty attacks across Europe, primarily against Jewish, Israeli-, American-, and Zionist-linked targets. Claimed incidents mentioned in the content include the 9 March firebomb or IED attack on a synagogue in Liège, a 13 March synagogue attack in Rotterdam, a 14 March attack on a Jewish school in Amsterdam, a 16 March attack on a commercial centre or the World Trade Center in Amsterdam, a 23 March attack in the United Kingdom involving ambulances associated with a Jewish community organization, and an April 2026 claim targeting a building associated with Christians for Israel in Nijkerk, Netherlands. The content also notes additional claims relating to Greece, France, and Haarlem, but assesses some of those as likely disinformation or unsupported by public evidence. Its observable presence was concentrated on Telegram, where it published or redistributed attack claims, propaganda, and geopolitical commentary. The group’s Telegram footprint was fragmented and unstable, with limited persistent content, heavy reliance on secondary or supporter channels for redistribution, and apparent removal of its primary Telegram channel by early April 2026. Secondary channels such as Safee al-Deen continued circulating material attributed to the group. Claim videos and posts were disseminated through Telegram and X channels linked to pro-Iranian networks, including channels associated with Iraqi Shia militias. The content specifically notes early dissemination through channels assessed as affiliated with Liwa Zulfiqar and Asaib Ahl al-Haq. HAYI messaging was primarily in Arabic, and the alleged official channels and branding reportedly contained inconsistencies, including misspellings and logo errors. Multiple sources in the content assess that HAYI may not be a mature, centralized militant organization. Instead, it is described as possibly functioning as a front identity, façade, or loosely coordinated media construct used to claim attacks carried out by locally recruited or externally recruited individuals. The Foundation for Defense of Democracies assessed that it may function less as a centralized organization and more as a front identity. The content highlights inconsistent media quality, lack of formal statements or leadership messaging, and dependence on redistribution through a broader Telegram ecosystem. The strongest reported indicators of Iranian alignment come from the group’s digital footprint and dissemination patterns. The International Centre for Counter-Terrorism (ICCT) assessed that the modus operandi and especially the online dissemination of HAYI claim messages were the main indicators of a link to Iran’s Islamic Revolutionary Guard Corps (IRGC). The content repeatedly places HAYI within a broader Iranian-aligned or IRGC-aligned Telegram ecosystem and notes overlap with channels tied to the so-called Islamic Resistance environment. Video content reposted by HAYI reportedly contained Sabereen News branding; Sabereen News is described in the content as a Telegram-based media outlet widely associated with Iranian-aligned networks and assessed by cited sources as showing strong indicators of links to the IRGC-Quds Force. The content also notes that HAYI claims and narratives were amplified through channels associated with Iraqi pro-Iranian militias. Operationally, the attacks described in the content were typically nighttime or early-morning incidents causing limited damage and intended more for intimidation and confusion than mass casualties. The ICCT characterized this pattern as consistent with Iranian hybrid warfare. The content further states that attackers were likely recruited locally, including youths on the margins of criminal gangs, and that this use of disposable local actors fits the broader pattern discussed in the reporting. Known alias: Ashab al-Yamin. Abbreviation used in the content: HAYI.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇳🇱 Netherlands
  • 🇬🇧 United Kingdom

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics6 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
TA0042
Resource Development
1 technique
T1585
Establish Accounts
T1585.001
Social Media Accounts
TA0001
Initial Access
1 technique
T1659
Content Injection
TA0011
Command and Control
1 technique
T1659
Content Injection
TA0040
Impact
1 technique
T1485
Data Destruction
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.