Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇮🇷 IR1 malware family

DieNet

Also known asDieNet

DieNet is a pro-Iranian, pro-Palestinian hacktivist group that emerged on Telegram in March 2025 and became one of the most prolific disruptive actors in the 2026 Iran-Israel conflict. It is repeatedly described as a major DDoS infrastructure supplier and primary volume driver for allied hacktivist groups, including within the Electronic Operations Room / Cyber Islamic Resistance coalition, where it acted as a central node alongside groups such as 313 Team. The group has also been referred to as part of the Electronic Operations Room of Islamic Resistance Axis. Content describes DieNet as structurally resembling a franchise with a core leadership circle and a wider ring of opportunistic operators, and one source notes it is believed to include Russian-speaking members with connections to Eastern European cyber communities. DieNet’s activity is centered on disruptive operations, especially high-volume DDoS attacks using rented DDoS-as-a-service infrastructure rather than bespoke malware. Reported techniques include TCP SYN floods, TCP RST floods, DNS amplification, NTP amplification, and Layer 7 application attacks. The group is described as providing structured target lists and automated check-host verification for allied groups. Its primary confirmed ATT&CK behavior in the content is Network Denial of Service (T1498). The group also uses Telegram messaging and propaganda to amplify psychological impact. Targets mentioned in the content span government, finance, telecommunications, transportation, healthcare, utilities, and other civilian and critical infrastructure sectors. The United States has been described as DieNet’s primary target since inception, with claimed attacks against U.S. transit, energy, financial, healthcare, and transportation entities, and warnings that it would attack the United States if it joined the conflict against Iran. The group also claimed attacks against Israeli websites and resources, GCC government and infrastructure targets in Kuwait, Bahrain, Jordan, Saudi Arabia, the UAE, and Qatar, as well as Indian government infrastructure and Cyprus. During the March 2026 escalation, DieNet was described as one of the most active pro-Iranian hacktivist groups and as a leading disruptive force in the broader pro-Iran ecosystem. The content also states that DieNet expanded campaigns into utility and civilian sectors and shared imagery allegedly showing accessed industrial control interfaces, PLC access, and OT/ICS-related screens. However, the same reporting emphasizes that many of DieNet’s claims involving ransomware, data theft, intrusion, and OT/ICS access were unverified, likely exaggerated, or inflated for propaganda effect. An announced ransomware strain, Locknet, and various exfiltration claims are specifically described as unverified. Known associations and amplifying peers mentioned in the content include 313 Team, Cyber Islamic Resistance, APT IRAN, Keymous / Keymous Plus, Fatimion Cyber Team, FAD Team, ALTOUFAN TEAM, Sylhet Gang-SG, OverFlame, DenBots Proof, Cyber Fattah, and Cyb3r Drag0nz. The group’s known alias in the provided content is DieNet.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Transportation
  • Banks

Where they target

Geographies tied to known operations.

  • 🇧🇭 Bahrain
  • 🇸🇦 Saudi Arabia
  • 🇯🇴 Jordan

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics24 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1590
Gather Victim Network Information
T1592
Gather Victim Host Information
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.005
Botnet
T1584
Compromise Infrastructure
T1584.005
Botnet
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1190
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
1 technique
T1078
Valid Accounts
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
TA0010
Exfiltration
2 techniques
T1537
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
4 techniques
T1491
Defacement
T1491.001×4
Internal Defacement
T1491.002
External Defacement
T1498×15
Network Denial of Service
T1498.001
Direct Network Flood
T1498.002
Reflection Amplification
T1499×2
Endpoint Denial of Service
T1565
Data Manipulation
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

IOCS

Observables

2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping19

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables2

Domains, IPs, and hashes tied to this actor, refreshed continuously.