Threat reportThreat IntelligenceTL-2026-2309
DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network
DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency (TL-2026-2309) is a medium-severity tracked intrusion set, first published 2026-09-03. It is attributed to Hamas with high confidence, maps to 10 MITRE ATT&CK techniques (T1102.002, T1573, T1583.001), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 1Hamas
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-2309
- Threat ID
- TL-2026-2309
- Severity
- MEDIUM
- Status
- MITIGATED
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- Hamas
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- financial-services, virtual-asset-service-providers, government administration, nonprofit-fundraising
- Target regions
- Gaza Strip, lebanon, turkey, iran, united states of america, Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency
Malware and tooling: telegram, Chainalysis Reactor, TRM Labs blockchain forensics
How DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency works
The U.S. Justice Department and FBI, using Chainalysis blockchain analytics, seized more than $560,000 in cryptocurrency raised by Hamas and its military wing, the al-Qassam Brigades, across five court-authorized actions from March 2025 to August 2026, and took over the group's donation infrastructure including its main website, AlQassam.ps.
On September 1, 2026, the Justice Department announced it had confiscated over $560,000 in cryptocurrency destined for Hamas and the Izz ad-Din al-Qassam Brigades, culminating a counter-terror-financing investigation led by the FBI's Albuquerque Field Office (with support from the FBI Counterterrorism Division, Cyber Division, and New York Field Office). Al-Qassam Brigades operatives used an encrypted Telegram group chat to direct supporters to a fundraising website and a rotating set of cryptocurrency donation addresses; human sources also identified a Telegram message directing supporters to contact an al-Qassam Brigades email address for donation instructions. Investigators, supported by Chainalysis blockchain analytics, traced funds moving from donation wallets through consolidation wallets and shared gas-funding wallets, across blockchain bridges (including Tron-to-Binance Smart Chain conversions with no apparent economic purpose other than concealing fund origin), and out through virtual currency exchange accounts (Binance, and reportedly Trust Wallet and Bybit) and at least one Lebanon-based over-the-counter (OTC) broker exhibiting money-mule-like transaction patterns.
Three federal seizure/freeze warrants were executed on March 25, 2025 (an initial ~$201,400 seizure from addresses that had received over $1.5 million in donations since October 2024), June 25, 2025, and October 10, 2025, proceeding under 18 U.S.C. § 981(a)(1)(G) (terrorism-related civil forfeiture) and 18 U.S.C. § 2339B (material support to a designated Foreign Terrorist Organization), which allowed asset seizure without a prior criminal prosecution of the foreign operatives involved. Court filings identified Bitcoin, Ethereum, Wrapped Ethereum, Tether (USDT), and Tron across 18 Tether-controlled addresses and three Binance accounts tied to the financing of a designated Foreign Terrorist Organization; reporting also indicates some exchange accounts in the fund-movement chain were registered using the identities of Palestinians living in Turkey and using Lebanese passports, consistent with KYC-evasion via fraudulent or mule identities. After the initial seizure, al-Qassam Brigades operators adapted by abandoning recurring gas wallets in favor of single-use, disposable donation addresses to frustrate tracing.
On July 29, 2026 and August 18, 2026, the FBI executed two further actions that seized the domains and servers al-Qassam Brigades controlled — including its primary website AlQassam.ps and the related AlAqsaFlood.org / Host.AlAqsaFlood.org infrastructure — allowing the Bureau to intercept in-progress donations and obtain contact information and online communication records for thousands of individuals who had reached out to Hamas-linked platforms seeking to donate. Reporting indicates this fundraising infrastructure was originally hosted on servers in Iran before being migrated to servers operated by companies with U.S.-based data centers. The al-Qassam Brigades' crypto-fundraising apparatus dates back at least to January 2019, when the group first solicited Bitcoin donations via social media posts before moving to a dedicated fundraising site (alqassam.net) offering donors a link (fund.alqassam.net) that displayed a QR code and wallet address to scan or copy; after prior takedowns the group adapted by embedding third-party payment processors directly into its fundraising web pages.
The operation is part of a broader, ongoing DOJ campaign against Hamas's crypto-enabled financing: in July 2025 the Department unsealed a related civil forfeiture complaint against approximately $2 million in digital currency tied to BuyCash Money Transfer and Exchange Company, a Gaza-based virtual-asset business operating since 2014 and owned by Ahmed M.M. Alaqad, which OFAC designated on October 18, 2023 under Executive Order 13224 for providing material support to Hamas (and, per the same designation, to al-Qa'ida- and ISIS-affiliated actors). TRM Labs' review of that case traced funds across nearly 150 wallets linked to BuyCash, including rapid inter-wallet transfers establishing operational links between addresses before liquidation through identified exchange accounts. Separately, Israeli police froze Hamas-linked Binance accounts in 2023, and Binance froze roughly 14% of over 1,500 wallets flagged by Israeli authorities in 2024.
Financial tracing indicates the fundraising network's donation addresses received approximately 1.57 million USDT between late October 2024 and March 2025, and Chainalysis/DOJ court filings estimate the network had received over $3 million in total cryptocurrency by November 2025 — meaning the ~$560,000 in FBI seizures represents only a fraction of funds actually raised, with the remainder presumed laundered out through the OTC/exchange off-ramp chain before interdiction. The fundraising infrastructure's hosting relied on an Iran-based provider in Tehran until spring 2026, when it was migrated to servers operated by companies with U.S.-based data centers — a jurisdictional shift that brought the infrastructure within reach of U.S. court orders and enabled the July-August 2026 seizure actions. This is not al-Qassam Brigades' first crypto-fundraising network to be dismantled: in August 2020, the DOJ announced what was then described as the largest-ever seizure of cryptoassets belonging to terrorist organizations, targeting parallel al-Qassam Brigades and Syria-based al-Qaeda-affiliated fundraising operations; Elliptic had first reported on the al-Qassam Brigades' Bitcoin solicitation campaign in April 2019, and later research tied a Syria-based exchange operating via Telegram from Idlib, BitcoinTransfer, and a Turkish national, Mehmet Akti, to laundering al-Qassam donations through a major Asia-based exchange — establishing a recidivist pattern across at least three enforcement cycles (2019-2020, 2023 BuyCash designation, and the 2025-2026 actions detailed here). Officials framed the actions as a continuing disruption campaign rather than a one-time strike. Assistant Attorney General John A. Eisenberg said the seizures 'deprive Hamas of resources it relies on to recruit and radicalize individuals online' and that the Department will 'continue to tighten the vise on Hamas's capacity for terror by infiltrating its online networks, confiscating its cryptocurrency, and shutting down its websites.' U.S. Attorney Jeanine Ferris Pirro (D.C.) said, 'Your networks are not secure, your crypto is vulnerable, and we will not stop until your ability to wage war is defeated.' FBI Cyber Division Assistant Director Brett Leatherman noted the Bureau 'will continue to use its authorities to intercept illicit funds and prevent terrorist organizations from exploiting digital networks.'
MITRE ATT&CK techniques used in TL-2026-2309
Command and Control
T1102.002 Bidirectional Communication; T1573 Encrypted Channel
Resource Development
T1583.001 Domains; T1583.003 Virtual Private Server; T1583.004 Server; T1583.006 Web Services; T1585 Establish Accounts; T1585.001 Social Media Accounts; T1585.002 Email Accounts
Reconnaissance
Remediation for DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency
Immediate actions
- Screen customers and counterparties against the OFAC SDN list for BuyCash Money Transfer and Exchange Company and Ahmed M.M. Alaqad before onboarding or processing transactions
- Block or flag transactions to/from AlQassam.ps, alqassam.net, fund.alqassam.net, AlAqsaFlood.org, Host.AlAqsaFlood.org and any successor domains/infrastructure referenced in the DOJ actions
- Report suspected Hamas-linked cryptocurrency solicitation activity to FinCEN and the FBI (IC3 or local field office)
- Flag virtual-asset-service-provider accounts opened with Turkish- or Lebanese-issued identity documents that exhibit mule-like rapid pass-through transaction patterns for enhanced KYC review
Longer-term hardening
- Integrate blockchain analytics (e.g., Chainalysis, TRM Labs) into AML/CFT transaction-monitoring programs for virtual asset service providers
- Strengthen KYC/AML controls at OTC brokers and cross-border remittance services with exposure to Gaza, Lebanon, Turkey, and other high-risk jurisdictions
- Monitor Telegram and other encrypted messaging platforms for terror-financing solicitation campaigns and rotating donation-address patterns
- Apply heightened scrutiny to cross-chain bridge transactions (e.g., Tron-to-Binance Smart Chain) that lack apparent economic purpose
Timeline of DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency
- Al-Qassam Brigades first solicits Bitcoin donations via social media posts, then launches a dedicated fundraising site (alqassam.net) offering a QR-code/wallet-address donation link (fund.alqassam.net).
- Elliptic first publicly reports on the al-Qassam Brigades Bitcoin solicitation campaign, later tying a Syria-based exchange operating via Telegram from Idlib (BitcoinTransfer) and Turkish national Mehmet Akti to laundering al-Qassam donations through a major Asia-based exchange.
- DOJ announces what was then the largest-ever U.S. seizure of cryptoassets belonging to terrorist organizations, dismantling a parallel al-Qassam Brigades and Syria-based al-Qaeda-affiliated crypto-fundraising network — establishing the recidivist enforcement pattern that the 2025-2026 actions continue.
- OFAC designates BuyCash Money Transfer and Exchange Company and owner Ahmed M.M. Alaqad under Executive Order 13224 for material support to Hamas.
- Al-Qassam Brigades donation addresses begin accumulating funds, receiving approximately 1.57 million USDT between late October 2024 and March 2025; the addresses seized in March 2025 had received over $1.5 million since this period, with total network receipts estimated at over $3 million by November 2025.
- FBI executes the first court-authorized seizure warrant, confiscating approximately $201,400 in stablecoins from al-Qassam Brigades donation addresses.
- FBI executes a second court-authorized seizure/freeze warrant against additional Hamas-linked cryptocurrency.
- DOJ unseals a civil forfeiture complaint against approximately $2 million in digital currency tied to BuyCash Money Transfer and Exchange Company and Ahmed M.M. Alaqad.
- FBI executes a third court-authorized warrant, freezing further Hamas-linked cryptocurrency assets.
- Al-Qassam Brigades' fundraising infrastructure, previously hosted with an Iran-based provider in Tehran, migrates to servers operated by companies with U.S.-based data centers — bringing it within reach of U.S. court orders and enabling the subsequent infrastructure-seizure actions.
- FBI Albuquerque Field Office seizes domains and servers controlled by al-Qassam Brigades, including its main website AlQassam.ps.
- FBI executes a further seizure of al-Qassam Brigades-controlled domains and servers, including AlAqsaFlood.org and Host.AlAqsaFlood.org, completing the infrastructure takedown.
- DOJ publicly announces the combined actions, totaling over $560,000 in seized cryptocurrency and full takeover of AlQassam.ps and related fundraising sites, releasing five supporting affidavits.
- Chainalysis publishes blockchain-analytics writeup detailing the fund-flow tracing behind the seizures.
Sources cited for DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency
- FBI Seizes Hamas Crypto Fundraising Network
- Justice Department Continues to Disrupt Hamas Terrorist Financing Schemes Through Seizures
- DOJ Targets Hamas-Linked BuyCash Exchange in $2 Million Civil Forfeiture for Terrorist Financing
- In Wake of Attack on Israel, Understanding How Hamas Uses Crypto to Fund Its Operations
- The US Takedown of Crypto-Linked Terrorist Financing
- FBI cracks Hamas crypto network, seizes $560,000 and exposes thousands of donors
- DOJ Seizes $560K in Hamas Crypto Cash, Unmasks Thousands of Donors
- FBI Seizes $560K in Crypto Bound for Hamas, Takes Over Fundraising Sites
- DOJ says Hamas crypto seizures reached $560,000 as FBI took over fundraising sites
- FBI, Justice Dep't seize $560,000 in Hamas cryptocurrency, takes over fundraising sites
Detection coverage for TL-2026-2309
As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2309 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.