← Back

Anonymous Islamic Army distributes anti-Israel ransomware under a narrative of “cyber-jihad” and ideological financing

Leer en Español
Print Share

Executive Summary

Anonymous Islamic Army published a message in Arabic presenting a ransomware tool oriented against Israeli systems. According to the actor, the tool was designed to execute only on devices associated with Israel by checking the time zone and Hebrew language before starting the encryption process.

The publication combines religious propaganda, an anti-Israel narrative and the public distribution of an offensive capability. The actor not only promotes the ransomware as an attack instrument, but also states that it is releasing it for third-party use, while keeping the decryption process and associated monetization under its own control.

The novel element of the case does not lie only in the malware itself, but in its public release under a model in which use is decentralized, while control over decryption and monetization remains, according to the actor, under its authority.

Key Judgments

  • Anonymous Islamic Army publicly presented an anti-Israel ransomware and framed it as a “cyber-jihad” tool directed against Israeli systems.
  • According to the actor, the malware validates the time zone and Hebrew language before starting encryption, with the declared objective of limiting its use to Israeli targets.
  • The publication turns the ransomware into a distributed offensive resource: the actor releases it for public use, but states that it retains control over decryption.
  • The declared model suggests an arrangement in which execution can be decentralized, while monetization and the ideological legitimacy of payment remain associated with the actor.

What Happened

Anonymous Islamic Army disseminated a message stating that “cyber-jihad” is no less important than confrontation on the physical battlefield, presenting it as a form of support for the effort against its adversaries. The actor then introduced a ransomware tool that, according to its description, was designed to operate only on Israeli devices.

The actor states that the malware checks the time zone and Hebrew language before starting encryption. According to that narrative, this restriction would prevent indiscriminate use of the tool and concentrate its impact on Israeli targets.

The publication includes a link to a GitHub repository where the artifact is distributed. The associated file, identified as encryption.exe, has the SHA1 hash c5c7373add6ee71ca05c310dc05ef72d4bcc522c. The repository also includes a README.txt that presents the tool as an advanced ransomware oriented exclusively against “Zionist systems”.

The README states that the ransomware uses AES-256 and that files would remain locked unless decrypted by the actor’s own team. It also states that the tool was not created for personal profit, but as a digital response to war crimes and attacks against civilians, according to the group’s narrative.

Operational Assessment

iQBlack assesses the publication as the public distribution of an ideologized ransomware tool. The malware has been in-the-wild for at least one month, but the central point of this communication is that Anonymous Islamic Army turns it into a publicly accessible tool. That decision modifies the operational model because the ransomware ceases to be a private resource and begins to function as a distributed instrument of digital aggression.

However, the actor does not fully relinquish control. According to its own message, the decryption keys would remain held by Anonymous Islamic Army and successful cases should be reported to the group. The declared condition for decryption would be the transfer of money to causes linked to Gaza, Sudan and other spaces presented by the actor as part of an oppressed community.

In operational terms, this suggests a hybrid model: use of the tool is opened to third parties, but the actor seeks to retain control over recovery, monetization and the ideological framing of payment. Execution is decentralized; decryption and the legitimacy narrative remain centralized.

The targeting logic described by the actor requires particular caution, because verification of Hebrew language and time zone may be consistent with an intent to limit the malware’s reach, but it does not guarantee actual exclusivity against Israeli systems. These checks may be incomplete, manipulable, faulty or removed by third parties once the artifact becomes publicly available.

Actor Context

Anonymous Islamic Army maintains a sustained focus on Israel as a target of its communication and public activity. In that context, the appearance of anti-Israel ransomware does not represent a deviation from the actor’s known profile, but rather an expansion of resources within a broader repertoire of digital harassment and operational propaganda.

The actor is not limited to a single methodology. Its activity should be understood as part of a hacktivist ecosystem in which visibility, mobilization, symbolic pressure and the availability of offensive tools can have as much value as direct technical impact.

In this case, the ransomware functions simultaneously as a technical artifact, a propaganda piece and a declared financing mechanism. That combination reinforces the assessment of a tool designed not only to produce negative impact on victims, but also to turn third-party participation into a form of ideological contribution.

Intelligence Significance

The relevance of this publication lies in the convergence of malware, propaganda and financing. Anonymous Islamic Army does not merely announce an offensive tool; it releases it publicly under a narrative of selective use against Israel. That decision may facilitate the participation of sympathizers, low-sophistication operators or opportunistic third parties, lowering the barrier to entry for ideologically motivated ransomware actions.

The declared model also introduces a particular financial dimension. According to the actor, decryption would depend on payments directed to causes linked to Gaza, Sudan and other spaces presented as part of an oppressed community. In this way, ransomware monetization is reframed as cause-based financing rather than individual profit.

That narrative should not be accepted uncritically, but it should be analyzed as part of the strategic value of the message. The actor attempts to present the tool as morally constrained, technically selective and politically justified. At the same time, the public release of the artifact may generate uncontrolled effects, including reuse against third parties, code modification or loss of control over the malware’s actual use.

Analytical Closing

Anonymous Islamic Army published anti-Israel ransomware and presented it as a public tool for digital aggression and ideological financing. According to the actor, the malware was designed to operate only against Israeli devices through language and time-zone checks, while decryption would remain under the group’s control.

Until full technical validation is available, iQBlack assesses the publication as a preliminary indicator of public distribution of offensive capability and not as confirmation of a successful ransomware campaign or exclusive targeting against Israel.

The model proposed by the actor — distributed use of the malware, centralized control over decryption and monetization reframed as contribution to a political-ideological cause — represents the immediate intelligence value of the case.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved