Violent Extremist Offensive Cyber Capabilities
This session examined extremist cyber operations, infrastructure targeting risks, and the convergence of online propaganda with operational cyber sabotage. It featured Bennett Clifford, Senior Threat Intelligence Analyst with Recorded Future’s Insikt Group and was moderated by Dr. Omar Mohammed, Senior Research Fellow at the Program on Extremism.
On May 14, 2026, the Program on Extremism at The George Washington University hosted “Violent Extremist Offensive Cyber Capabilities,” as part of its Global Extremism Papers webinar series. The session was moderated by Dr. Omar Mohammed, Senior Research Fellow at PoE, and featured Bennett Clifford, Senior Threat Intelligence Analyst with Recorded Future’s Insikt Group, formerly a Senior Research Fellow at PoE and co-author of Homegrown: ISIS in America.
Clifford analyzed the pathways by which Domestic Violent Extremism (DVE) actors could move from aspiration to operational cyber-attack capability. The analysis, drawn from a longer internal report at Recorded Future, used course of action (COA) analysis - a structured intelligence-community technique - to assess how DVEs might acquire offensive cyber capabilities and which methods would be most dangerous and most likely acquired.
Clifford identified two central findings. First, while U.S.-based DVEs have frequently expressed interest in advanced cyber-attack capabilities, they remain unlikely to achieve them without either significant assistance from financially or politically motivated cyber threat actors, or new technology enabling in-house development. Second, two ongoing shifts are increasing the near-term probability of a breakthrough: growing online interaction between DVEs and cyber threat actor communities, and the rise of generative AI tools that are lowering the skill barrier for cyberattack development.
The COA analysis weighed three possible pathways: DVEs purchasing capabilities from financially motivated cybercriminals (most dangerous, least likely); DVEs collaborating with politically motivated activist groups (moderate likelihood and danger); and DVEs developing capabilities in-house (most likely, least immediately dangerous, but increasingly boosted by generative AI tools). Case studies included a 2023 neo-Nazi group deploying a purchased remote access trojan, a website defacement by anarchist extremists working with an activist collective, and an imprisoned Terrorgram-linked accelerationist calling for supporters to develop skills to hack critical infrastructure.
Clifford situated current DVE cyber capability roughly at the “iteration” stage of the VNSA technology adoption curve, short of a “breakthrough,” while cautioning that convergence with broader threat-actor communities - such as the loosely organized network law enforcement refers to as “the Com” and generative AI development are accelerating that timeline.
Clifford noted that coordination challenges posed by simultaneous cyber and physical attacks require specialized in-group expertise rather than a single individual, and discussed the strengths and limitations of course of action analysis as a predictive intelligence technique versus academic, descriptive research. He discussed the growing crossover between cyber and physical threat actors within networks like “the Com,” pointing to threat actors publishing instructional material for each other across cyber and physical tactics as one indicator. Clifford also cited recent developments since the paper’s publication, including the role of chatbot assistance in a 2025 shooting at Florida State University, as evidence that AI-assisted attack planning may be advancing faster than AI-assisted cyberattacks specifically.
On the path forward, Clifford recommended that law enforcement focus on disrupting malware-as-a-service providers and initial access brokers at the source, cautioning against applying a uniform counterterrorism framework to loosely affiliated online networks that include extortionist groups and cybercriminals alongside ideologically motivated extremists. He argued that these distinct threat actor types require tailored responses based on their actual tactics rather than a single label.