Menu
Browse

Cyber Threat Actor: Hezbollah

Aliases 4 aliases
Actor Type Location Known Incidents
 Icon
Activist
Lebanon
2 incidents
Profile

Hezbollah, also known as the Party of God, Hizb Allah, or Hezb, is a Lebanon‑based organization that has been identified in open sources as conducting cyber operations. The group uses multiple aliases in its communications and maintains a presence within Lebanon’s political and militant landscape. Public reporting ties the actor to a dedicated cyber unit referred to as Kadimon, which has claimed responsibility for specific intrusions against Israeli targets.

In February 2016 Hezbollah’s Kadimon unit asserted that it had gained unauthorized access to security cameras across a range of Israeli locations, including sensitive government facilities, public streets, cafes and offices. The attackers released a promotional video titled “Shattering the Illusion” that displayed footage obtained from these compromised cameras, thereby demonstrating an ability to monitor both military and civilian spaces. Alongside the camera breach, the group claimed to have previously breached thousands of websites and warned of further escalation if their demands were not met. Israeli military officials responded by emphasizing existing deterrence measures, though they did not publicly confirm the validity of the intrusion claims or the nature of the footage shown.

The observed tactics in this operation involved exploiting vulnerabilities in video surveillance systems to obtain live feeds and then disseminating that material through a coordinated media release. No specific malware families, exploit kits or initial access vectors were detailed in the available reporting, so the profile refrains from speculating on those technical elements. The 2016 incident stands as a representative example of Hezbollah’s publicly disclosed cyber activity, illustrating a pattern of targeting Israeli security infrastructure to achieve propaganda and intimidation objectives. This activity underscores the group’s willingness to leverage cyber capabilities as part of its broader strategic messaging.

Incidents
Attributed incidents available to members
2 incidents
Sources
Sources available to members
0 sources