ThreatSec is a hacktivist group established in May 2023 and associated with politically motivated intrusions and disruptive attacks. It adopted a pro-Israel position during the Israel–Hamas conflict in October 2023. Its documented targeting includes the Palestinian internet service provider AlfaNet, whose servers it compromised and shut down, as well as targets in Russia and the technology company Genesys. Technical details of its intrusion methods remain unavailable. ThreatSec is a founding member of FiveFamilies, an alliance formed in August 2023 comprising ThreatSec, GhostSec (Ghost Security), Stormous, BlackForums, and SiegedSec. It also has publicly acknowledged associations with KittenSec. These relationships do not establish ThreatSec's participation in the ransomware operations or other attacks conducted by associated groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Member of the 'Five Families' alliance with SiegedSec and other groups, which collectively claimed multiple breaches before becoming inactive.
Pro-Israeli hacktivist activity; reportedly conducted a destructive intrusion against Palestinian ISP Alfanet, shutting down servers.
A pro-Israel hacktivist group reportedly responsible for compromising Palestinian internet service provider AlfaNet. The content does not identify the intrusion method, malware, or vulnerabilities involved.
Referenced as an associated hacktivist operation linked by KittenSec in the context of planned targeting of additional NATO countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.