Where the Trail Leads: Inside Al-Shabaab’s Digital Media Network

Jihadist organizations have adapted to a digital environment in which communication is no longer dependent on a single website, forum or dedicated platform. Messaging applications, social networks and alternative publishing platforms allow extremist groups to distribute propaganda, communicate narratives, publish claims and redirect audiences between different online spaces. This also creates a challenge for investigators: the most useful evidence may not be found on an account that openly identifies with an extremist organization, but somewhere further along the chain of distribution.

Al-Shabaab is a particularly relevant example. The Somali jihadist organization has developed a sustained media presence around its activities in Somalia and the wider region, using digital channels to communicate its narratives and disseminate material associated with the group. Its media activity extends beyond individual posts and can involve multiple platforms, accounts and distribution points.

For an investigator, this creates a more difficult question than simply asking whether Al-Shabaab has an online presence. The more useful question is how that presence can be traced when its content is dispersed across different users and platforms, including spaces that may not appear extremist at first glance.

This investigation was designed around that question.

Additionally, another objective was to test how effectively StealthMole could support investigations into jihadist terrorism and different forms of extremist activity. Rather than beginning with known infrastructure and checking whether the platform could find it, the objective was to start with a basic search and see whether StealthMole could uncover and connect the wider media, communication and distribution ecosystem surrounding the group.

The investigation therefore became a test of the platform's ability to turn a relatively weak initial signal into a more meaningful intelligence picture.


The Ideology Behind the Network

Al-Shabaab's online presence needs to be understood in the context of its broader jihadist identity. The group is not simply an armed actor that happens to use the internet. Its media activity forms part of how it communicates its worldview, presents its activities and maintains an information presence beyond the physical areas in which it operates.

That makes its media infrastructure particularly important from an intelligence perspective. When an extremist group publishes material, the content itself may be only one part of the investigative picture. The more useful question can be how that material moves. Who republishes it? Which accounts repeatedly direct audiences toward the same source? Which platforms are used when another platform becomes difficult to access? Which websites, bots or channels appear repeatedly alongside official material?

These questions matter because extremist communication networks are rarely limited to one account or one website. A single media organization can have several points of distribution, while supporters or other users may reproduce its material elsewhere. As a result, an investigator looking only for an account explicitly identifying itself with the group can miss a substantial amount of the surrounding activity.

The distinction between official media infrastructure and secondary distribution is also important. An account sharing Al-Shabaab material is not automatically an Al-Shabaab operative. Likewise, a Telegram group containing Al-Shabaab-related posts is not necessarily an Al-Shabaab-controlled group. The evidentiary value of each finding depends on what can actually be established about the relationship.

This distinction became particularly important during this investigation. The investigation encountered a mixture of clearly identifiable Al-Shabaab media references, repeated distribution activity by individual users, official communication points and apparently unrelated communities in which the material appeared. Treating all of these entities as one homogeneous network would have overstated the evidence.

Instead, the investigation followed a narrower principle: use confirmed media points as anchors, then examine how those points are referenced and redistributed across the wider digital environment.


One Keyword, One Unexpected Lead

The investigation began in StealthMole's Telegram Tracker with a deliberately broad search for:

  • al-Shabaab

StealthMole returned:

  • 361 Telegram messages
  • 2 Telegram users
  • 20 images
  • 190 documents
  • 43 other files

At first glance, the result did not immediately point toward an obvious Al-Shabaab-operated channel. One of the relevant results came from a Telegram channel titled:

  • ملتقى مهندسي الميكاترونكس

The channel was accessible at:

  • https://t.me/mech*****3

The channel presented itself as a mechatronics engineering community and had 1,180 members. Its visible content included technical material, including a pinned message relating to robotic simulation, robotic arms and agricultural pesticides.

That made the initial discovery more interesting, rather than less.

The search had not simply returned an obviously extremist channel. Instead, StealthMole had surfaced Al-Shabaab-related material within a community whose visible identity was technical and unrelated to jihadist activity. Rather than assuming the channel itself was connected to Al-Shabaab, the next step was to determine who had posted the relevant material and whether the same activity appeared elsewhere.

A message with the following ID provided the first meaningful pivot.

  • 1307071588_30161

The message was associated with:

  • Telegram user ID: 8008400988
  • First name: سويلم
  • Username: @sal*******6

The account information available through the investigation did not provide a last name, phone number or biography.

The message contained the hashtags:

  • #Somalia
  • #Mogadishu
  • #Alshabaab
  • #AS

It also contained:

  • https://shahadanews.info/?p=27068

Moreover, the accompanying image in the message was identified as an official Al-Shabaab photo.


The Account Behind the Message

Rather than stopping with the single message, the investigation pivoted on @sal******6 inside StealthMole's Telegram Tracker.

This produced four messages from the same user within the Mechatronics channel. The significance of this result was the repetition.

The first finding could have been treated as an isolated instance of a Telegram user sharing extremist material. The additional messages made that explanation less useful. The same account was repeatedly circulating Al-Shabaab-related material and, importantly, repeatedly exposing additional communication points associated with Shahada News, the official media house of al-Shabaab group.

The investigation therefore moved from content identification to pattern identification.

Among the recurring contact points were:

  • @Akh**************bot
  • https://chirpwire.****/Sha***********y
  • https://bsky.app/profile/sh******news.bsky.social

Another message contained:

  • https://shahadanews.info/?p=27054

The value of @sal******46 was consequently not that the available evidence proved the account belonged to Al-Shabaab. It did not. What the evidence did establish was that the account repeatedly circulated Al-Shabaab-related material and, in doing so, exposed several communication points that could be investigated independently.

This distinction is important for attribution. The account could confidently be treated as a distribution point and investigative pivot, but not automatically classified as an Al-Shabaab member or operative.


Following the Media, Not Just the User

The most important pivot in the investigation was the move from @sal******6 to Shahada News.

Shahada News is a known Al-Shabaab media house responsible for official communications. This gave the recurring references to its media points a substantially different evidentiary value from an ordinary social-media account reposting extremist content.

The investigation identified Shahada News across several platforms.

On ChirpWire:

  • https://chirpwire.net/Sha********cy

Its available profile information showed:

  • Handle: @Sha************cy
  • Bio: Press coverage of Somalia, East Africa and the Islamic world.
  • Location: Somalia
  • Member since: July 2024
  • 4,141 Chirps
  • 1,421 Followers
  • 24 Following

The account was actively used to publish Al-Shabaab-related material, including claims, official statements from leaders and videos. Its activity also established that the media presence extended beyond Telegram rather than being confined to a single messaging platform.

A Bluesky presence was also identified:

  • https://bsky.app/profile/sh************s.bsky.social

The significance of this finding was not simply that Shahada News had another social-media account. It showed that the same media operation had identifiable points of presence across different communication environments, giving investigators multiple places from which to observe activity and identify further distribution paths.

The investigation also encountered several Telegram-based contact points associated with the wider media ecosystem, including:

  • @Wakalathhahbot
  • @wakkkalaatshahadabot
  • @akhbaralameslamibot
  • @Akhbaralalamaslambot

Additional bot names surfaced during subsequent searches, including:

  • @ekhbaralambot
  • @Shawanewsagencybot
  • @Ehdathebrazbot
  • @Ekhbarislamworldbot
  • @SHWAEKHBOT
  • @hdathebrazbot

The broader finding was therefore stronger than any individual username: Shahada News appeared to operate within a multi-platform communication environment, with Telegram bots and accounts providing additional routes to material and external platforms providing further distribution.


The Network Starts to Take Shape

The next pivot came from the Bluesky profile:

  • https://bsky.app/profile/sha********s.bsky.social

Searching this identifier in StealthMole's Telegram Tracker surfaced multiple messages that referenced the same media ecosystem.

Clearly identified message IDs included:

  • 1307071588_30046
  • 1307071588_30045
  • 1307071588_30006
  • 1307071588_30001
  • 1307071588_29894

The results also exposed additional Telegram user IDs:

  • 8042389197
  • 6738658884
  • 7760032048

The available evidence did not provide enough information to attribute these users to Al-Shabaab, so they remained unresolved.

More important were the recurring infrastructure and communication references that appeared across the results:

  • https://shahadanews.info
  • @Wakalathhahbot
  • https://chirpwire.***/Sha************cy
  • https://bsky.app/profile/sha*********s.bsky.social

A private Telegram invite was also surfaced:

  • https://t.me/+vLVTo_hNyaU0Mzg0

Other messages exposed additional contact points, including:

  • @wakkkalaatshahadabot
  • @akhbaralameslamibot

A Facebook page was also visible:

  • https://www.facebook.com/News.of.the.World46

The significance of this stage was the cross-platform recurrence.

The investigation was no longer dependent on a single Telegram account. The same media identity was appearing through Telegram, ChirpWire and Bluesky, while Telegram searches were simultaneously revealing bots, private channels and other users connected to the circulation of the material.

This made the digital environment more intelligible. The network did not appear as one clean diagram with a central account and clearly labelled affiliates. Instead, it emerged through repeated references between different platforms.

That is a more realistic picture of extremist online activity: some nodes can be confidently identified, some can be linked through repeated evidence, and others remain unknown until additional information becomes available.


Beyond the Obvious

One of the most useful findings came from returning to the original Telegram community:

  • https://t.me/mech*******3

The purpose of this pivot was straightforward: determine whether the initial result was simply an isolated message from @sal*******6, or whether other Al-Shabaab-related activity existed within the same environment.

The answer was the latter.

Multiple Al-Shabaab-related messages and videos had been posted by users other than Salman1446. This was significant because it changed the interpretation of the original channel.

The channel itself remained a mechatronics community, rather than an Al-Shabaab channel. Its visible identity was technical, it had 1,179 members, and its pinned content concerned engineering-related subjects.

Yet StealthMole surfaced extremist-related material inside that environment.

Among the material identified was a Shahada-branded post from November 2024 containing:

  • https://shahadaagency.net/?p=24056

Another post, dated around November 17, 2024, promoted:

  • @Siham_Al_Khair_04_bot

and

  • https://t.me/Siham_Al_Khair_04_bot

The accompanying Arabic material referred to jihadist and mujahideen-related news and content.

A Somali-language post dated around November 20, 2024 provided another example. Its headline was:

  • WEERAR LAGU QAADAY FARIISIN MALEESHIYAADKA MURTADIINTA AY KU LAHAAYEEN DULEEDKA DEEGAANKA BIRTA DHEER

The post referenced:

  • WILAAYADA ISLAAMIGA EE JUBBADA HOOSE

and contained several external distribution points:

  • https://t.me/+s-fy3YJKuDo5Yml0
  • https://www.facebook.com/News.of.the.World46/videos/1641062710140510
  • https://archive.********/index.php/s/FtrgGns29Lgmf5t
  • https://watch******e.**/h/other/post/247502/deg-deg-daawo-weerar-lagu-qaaday

Another Shahada-branded Arabic post from around November 6, 2024 concerned an alleged attack involving government militias and Al-Shabaab around Kismayo and Lower Juba.

These findings matter for two reasons.

First, they showed that the presence of Al-Shabaab-related material in the mechatronics group was not dependent on Sal*******6 alone. Multiple users were posting or distributing such content.

Second, the finding illustrates why investigations based only on obvious extremist channels can miss relevant activity. The community did not advertise itself as an extremist space. Its primary identity was technical, yet extremist media was nevertheless present within it.

That does not establish that the administrators or members of the channel as a whole were affiliated with Al-Shabaab. There is insufficient evidence for that conclusion.

What it does establish is narrower and more useful: Al-Shabaab-related material was being circulated within a broader Telegram environment that, on its face, was unrelated to jihadist activity.


The Media Trail Goes Further

The investigation then pivoted from the Bluesky reference to the ChirpWire account:

  • https://chirpwire.net/Sha*************cy

Searching for this identifier in StealthMole surfaced a series of Telegram messages spanning several months. The references to Shahada News were not confined to one day or one Telegram user. StealthMole was surfacing repeated references to the media operation across a period extending from November 2024 into February 2025.

The same search also exposed a growing collection of Telegram bot/contact identifiers, including:

  • @wakkkalaatshahadabot
  • @akhbaralameslamibot
  • @ekhbaralambot
  • @Shawanewsagencybot
  • @Ehdathebrazbot
  • @Ekhbarislamworldbot
  • @SHWAEKHBOT
  • @hdathebrazbot

A private Telegram invite was also identified:

  • https://t.me/+zwcrODfjyRESZDkO

The chronology also demonstrated that the media ecosystem had multiple distribution mechanisms operating over time. Telegram posts could point toward external social platforms, while searches for those external identifiers could lead back to Telegram messages containing additional contact points.


When the Trail Changes

One of the more unusual findings concerned the domain:

  • https://shahadanews.info

The domain appeared repeatedly during the investigation and was directly referenced in Al-Shabaab-related Telegram material, including:

  • https://shahadanews.info/?p=27068
  • https://shahadanews.info/?p=27054

Its historical appearance made it relevant to the investigation.

However, when the domain was accessed during the investigation, it no longer presented Al-Shabaab-related material. Instead, it currently hosts Norwegian-language casino content, including references to new casinos and gambling-related reviews.

This creates an important intelligence distinction between historical evidence and present-day infrastructure.

The historical Telegram references establish that shahadanews.info was being used as a destination in Al-Shabaab-related communications at the time those messages were circulated. Its current content, however, does not support describing the domain as an active Al-Shabaab website.

The available evidence does not establish what caused the change. Possible explanations could include later repurposing, transfer, expiration and re-registration, compromise or another change in control, but none of these can be established from the evidence collected in this investigation.

At the same time, the investigation identified a separate currently active website:

  • https://sha*************ws.***

The site presents itself as Shahada News Agency, with Arabic branding and sections covering news, reports, photographs/articles, studies and translations, and opinion-related content. Its current presentation is consistent with the Shahada News media identity encountered through the other investigation pivots.

The distinction between the two domains is important. It prevents the historical shahadanews.info reference from being incorrectly treated as evidence of current infrastructure while preserving its relevance as part of the historical communication trail.


Conclusion

The investigation showed that Al-Shabaab-related media activity extends beyond clearly identifiable extremist channels and can surface within broader online communities through repeated redistribution. Shahada News emerged as the strongest identifiable anchor in the network, with its presence recurring across Telegram, ChirpWire, Bluesky and multiple Telegram-based contact points.

The findings also highlight the importance of separating media infrastructure, distribution activity and attribution. While the evidence establishes a clear connection to Shahada News as an official Al-Shabaab media operation, it does not justify treating every user, channel or bot encountered along the trail as an Al-Shabaab affiliate. The investigation was therefore most useful not for producing a simple list of associated accounts, but for revealing the wider communication environment surrounding the group's media activity.

Most importantly, StealthMole made that environment discoverable from a single broad keyword. By allowing individual messages, users and URLs to become investigative pivots, the platform helped turn an initially isolated Telegram result into a broader view of how Al-Shabaab-related material was being distributed across platforms.


Editorial Note

As with most investigations into cyber and dark-web activity, the available evidence rarely provides absolute attribution or a complete picture of every relationship. Accounts can be repurposed, domains can change hands, content can be redistributed by users with different motivations, and an apparent association does not always establish operational control.

This case demonstrates the value of following those uncertainties rather than forcing premature conclusions: StealthMole helped connect individual pieces of historical and cross-platform evidence while still allowing unresolved entities and attribution gaps to remain unresolved.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com


Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report