Predatory Sparrow, also known by the Persian name Gonjeshke Darande and sometimes referenced as Indra, is a sophisticated, destructive cyber actor focused primarily on Iranian targets. The group publicly presents itself as an anti-regime or pro-Iranian-people hacktivist entity, but it is widely reported and commonly assessed as Israel-linked, with some reporting alleging state sponsorship or alignment with Israeli military or intelligence interests. Publicly available evidence supports describing the actor as a highly capable sabotage-oriented threat group, while direct official confirmation of state control remains unavailable. The actor emerged publicly by 2021 and is best known for disruptive and destructive operations against Iranian critical infrastructure and strategically sensitive civilian systems. Claimed and widely reported operations include attacks on Iran’s fuel distribution infrastructure in 2021 and again in 2023, disruptive activity affecting transportation-related systems, a 2022 operation against the Iranian steel sector that reportedly caused physical consequences at a production facility, and later attacks against Iranian banking and cryptocurrency infrastructure in 2025. Predatory Sparrow has also been associated with operations targeting Iranian state media and communications-related entities. Predatory Sparrow’s targeting pattern centers on sectors with high symbolic, economic, and operational value to the Iranian state, including energy, financial services, transportation, government-linked infrastructure, military-adjacent entities, and cryptocurrency platforms alleged to support sanctions evasion or regime-linked finance. Reported victims and affected environments include fuel station networks, banking systems, steel production, military-linked infrastructure, and a major Iranian cryptocurrency exchange. The group’s operations have repeatedly produced real-world disruption, including outages in fuel distribution, payment processing, and banking services. The actor demonstrates capabilities consistent with advanced post-compromise sabotage and operational disruption. Reported tradecraft includes destructive malware and wiper-style effects, compromise of central management infrastructure, disabling or soft-bricking endpoint devices in operational environments, data destruction, service disruption, and public claim-and-message operations designed to amplify political impact. In financial-sector operations, the group has also been reported to steal and deliberately render cryptocurrency unusable, combining technical disruption with coercive political signaling. Public reporting further indicates data leakage and publication of internal materials in some operations. Predatory Sparrow is notable for operating at the boundary between hacktivism, covert state action, and cyber sabotage. Its messaging is disciplined and politically framed, often portraying attacks as retaliation against the Islamic Republic, the IRGC, or regime-linked institutions. The actor is therefore best characterized as an Israel-linked, anti-Iran destructive cyber actor specializing in high-impact sabotage against critical and strategically important Iranian infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Mentioned only as a comparison case for destructive anti-Iran operations; not attributed to the incidents discussed here.
Israel-linked targeted cyber sabotage against Iranian industrial and financial infrastructure intended to damage state capacity, undermine confidence, and disrupt support networks.
Linked to disruptive cyberattacks in Iran affecting fuel distribution and banking systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.