GlorySec is a pro-Israel hacktivist group active in conflict-driven cyber operations. The group has publicly aligned itself with Israel in the Israeli-Palestinian conflict and with Azerbaijan in the Azerbaijan-Armenia conflict. It has claimed participation in operations branded as #OPArmenia and #OPPalestine and stated that it has taken over websites, indicating a focus on politically motivated disruptive and defacement-style activity rather than covert long-term intrusion. GlorySec appears in the broader ecosystem of hacktivist actors involved in the cyber spillover surrounding the October 2023 Israel-Hamas war, where common tactics across aligned groups included website defacements, distributed denial-of-service attacks, and data breaches against government, critical infrastructure, media, and private-sector targets. High-confidence reporting directly ties GlorySec to pro-Israel hacktivism and website takeover activity; additional capabilities or organizational structure are not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as one of several groups that reportedly announced plans to leave Telegram.
Pro-Israel hacktivist group focused on web penetration and website takeovers, supporting Israel and planning continued operations against Palestinian and Iranian targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.