Threat Actor Characterization
HARM Alliance
ID: 5c6b35ea1356a1168397df22c30e7b2072268| HARM | HARM Team | HA********** | HA***** |
| HA****** | — | — | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
HARM Alliance is an emerging pro-Russian hacktivist alliance operating mainly through Telegram-based propaganda, alliance announcements, and opportunistic intrusion or data-theft claims. Current public reporting most strongly supports monitoring it as a coalition-oriented symbolic disruption actor targeting Western- and Israel-linked environments.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1583 | Acquire Infrastructure | TA0042 |
|
| T1584 | Compromise Infrastructure | TA0042 |
|
| T1190 | Exploit Public-Facing Application | TA0001 |
|
| T1078 | Valid Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1005 | Data from Local System | TA0009 |
|
| T1020 | Automated Exfiltration | TA0010 |
|
| T1589 | Gather Victim Identity Information | TA0043 |
|
Classification: Unclassified / Open Source Intelligence (OSINT) — TLP:WHITE
Category: Hacktivism / politically motivated cyber activity - Origin: Russia-aligned ecosystem
Author: iQBlack CTI Team
Executive Summary
HARM Alliance is an emerging Telegram-centric hacktivist group operating inside the broader pro-Russian cyber-propaganda environment. Publicly observable material indicates that the group presents itself as a “Hacker Alliance - Righteous Mission,” uses Telegram for branding and coordination, and publishes claims involving data theft, politically framed targeting, and at least one SCADA-themed intrusion claim. Confidence is medium that HARM Alliance is a real and active group identity rather than a purely cosmetic label.
Available evidence does not support treating HARM Alliance as a mature intrusion set with deeply documented tradecraft. Instead, the group is best modeled as a low-to-medium maturity alliance-style cluster whose operational value lies in propaganda, symbolic targeting, opportunistic exfiltration claims, and ecosystem-level alliance signaling. Its channel description, visible admin/support handles, and alliance announcements indicate deliberate brand construction rather than a one-off campaign artifact.
Free Preview
Free Preview
Free Preview
Free Preview
Free Preview
Free Preview