Predatory Sparrow, also known as Gonjeshke Darande, is a pro-Israel, Israel-linked threat actor that has been publicly active since at least 2021 and has at times presented itself as an Iranian opposition or hacktivist group defending Iranian citizens against the Islamic Republic. Public reporting and multiple cited sources describe the group as suspected of having state links, with some researchers believing it is linked to Israeli military intelligence, though official Israeli control is not confirmed in the provided content. Additional aliases mentioned in the content include Indra, Adalat Ali, and MeteorExpress. The group is associated with targeted cyber sabotage and disruptive or destructive operations against Iranian critical infrastructure and state-linked entities. Reported and claimed targets include Iranian rail assets and transportation infrastructure, the fuel distribution system, state media infrastructure, the steel sector, banking systems, and cryptocurrency infrastructure. Specific incidents mentioned in the content include the October 2021 disruption of Iran’s fuel distribution system affecting approximately 4,300 gas stations; prior 2021 attacks against Iranian rail assets; a June 27, 2022 operation that caused a serious fire at an Iranian steel production facility; a June 2025 attack on Bank Sepah that reportedly destroyed data and caused widespread banking and payment outages, including knock-on effects at fuel stations; and a June 2025 breach of the Nobitex cryptocurrency exchange. In the Nobitex incident, Predatory Sparrow claimed to have stolen roughly $90 million in digital assets, sent the funds to vanity addresses containing variations of anti-IRGC phrases, effectively rendering the funds unusable, and published Nobitex source code and internal documentation. The group accused Nobitex of supporting sanctions evasion and terror financing. The content also states the group has claimed attacks against Iranian steel, fuel, banking, and cryptocurrency infrastructure, and has been linked to significant disruptions in Iranian fuel distribution and banking systems. The provided content characterizes Predatory Sparrow as capable of sophisticated, coordinated operations over several years, including use consistent with wiper malware and destructive effects. It is repeatedly described as a hacktivist or purported hacktivist group with suspected state links, and as an example of Israel-linked cyber sabotage directed at Iranian state capacity, public confidence, and financial or military-support networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Israel-linked targeted cyber sabotage against Iranian industrial and financial infrastructure intended to damage state capacity, undermine confidence, and disrupt support networks.
Linked to disruptive cyberattacks in Iran affecting fuel distribution and banking systems.
Conducted a 2025 cyberattack on Nobitex that disrupted the Iranian cryptocurrency exchange's operations.
Claimed responsibility for breaching Nobitex, stealing approximately $90 million in digital assets, and leaving politically themed messages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.