DarkStormTeam is a hacktivist threat actor that has been publicly associated with disruptive cyber operations during periods of Middle East geopolitical escalation. The group has been observed claiming distributed denial-of-service activity and data-leak operations, particularly against Israeli financial entities, with some spillover targeting in Saudi Arabia. Available reporting places the group among a broader ecosystem of politically aligned or opportunistic hacktivist actors active during the 2026 Israel-Iran crisis. The actor’s demonstrated behavior is centered on disruption and coercive signaling rather than stealthy long-term intrusion. High-confidence activity includes claimed DDoS operations and claimed data-leak activity. In the broader campaign environment in which the group appeared, hacktivist operations were dominated by service disruption, website defacement, and claimed breach activity against government, financial, aviation, telecommunications, and other critical targets; however, only DDoS and data-leak activity are directly attributable here at high confidence. The targeting of Israeli financial organizations indicates a politically motivated focus aligned with regional conflict dynamics rather than conventional cybercrime. DarkStormTeam should be assessed primarily as a hacktivist actor engaged in disruptive and reputational attacks. Based on the available facts, the group’s dominant motivation is hacktivism. Attribution to a specific state sponsor or country of origin is not supported at high confidence by the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.