Al-Qassam Brigades
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Al‑Qassam Brigades, also known as the Izz al‑Din al‑Qassam Brigades, constitute the military wing of the Hamas movement and operate primarily from the Palestinian territories. Public sources identify the group as a Palestinian militant organization that has claimed responsibility for cyber operations aimed at Israeli audiences. Their known activity focuses on infiltrating Israeli broadcast media to interrupt regular programming with audiovisual content that serves a propaganda purpose. The stated intent behind these intrusions appears to be disruption of normal information flow and the dissemination of messages intended to influence public perception during politically sensitive periods. No public reporting attributes financial gain or traditional espionage goals to these actions, emphasizing instead a strategic objective of psychological impact and message amplification.
In the observed operations the group employed a technique of hijacking live television or news channel feeds, replacing the legitimate broadcast with a pre‑produced clip that combined religious imagery, Quranic text, and the Islamic call to prayer accompanied by overlaid Hebrew statements. The 2014 incident involved compromising an Israeli television broadcaster’s signal to display threatening missile imagery targeting major Israeli cities and accompanying text, demonstrating the ability to manipulate broadcast infrastructure for intimidation. Two years later, on 29 November 2016, the same or a closely linked entity interrupted the evening programming of two major Israeli news channels with a thirty‑second segment showing Muslim holy sites, Quranic verses, and the Adhan while overlaying Hebrew phrases that referenced divine punishment and recent wildfires. Both episodes were timed to coincide with legislative debates concerning the regulation of the Adhan in Israel, indicating that the attackers selected moments of heightened public sensitivity to maximize the reach of their narrative. These publicly reported operations illustrate a repeatable pattern of using broadcast signal intrusion as a primary tool, without evidence of malware deployment, exploit kits, or credential‑theft tactics in the disclosed descriptions.
Incidents
Attributed incidents are available to members.
3 incidents