DarkBit, also tracked by Microsoft as DEV-1084, is an Iran-aligned destructive and ransomware-style intrusion set associated with the broader Iranian cyber ecosystem and widely linked to MOIS-aligned activity overlapping with or supporting MuddyWater. The actor emerged publicly in 2023 and is known for using a fake hacktivist persona to provide plausible deniability while conducting politically themed operations against Israeli targets. DarkBit is best known for the February 2023 attack on the Technion Israel Institute of Technology. In that operation, the actor combined data theft claims with file encryption and coercive messaging, presenting itself as a hacktivist entity while operating in a manner consistent with Iranian state-aligned disruptive activity. Reporting has described DEV-1084 as partnering with MERCURY, now tracked as Mango Sandstorm or MuddyWater, and conducting post-intrusion and destructive operations across both on-premises and cloud environments. Operationally, DarkBit has used Windows ransomware written in Go and protected with obfuscation. Observed behavior includes encrypting victim files, dropping ransom notes, deleting shadow copies, and using Windows Restart Manager functionality to terminate processes or release file locks that would interfere with encryption. The actor has also been associated with exfiltration claims and extortion messaging, indicating a blend of destructive, psychological, and financially framed tactics. Despite the ransomware presentation, DarkBit is frequently assessed in the context of Iranian state-linked operations rather than ordinary cybercrime. DarkBit fits a broader Iranian pattern of using front groups and hacktivist branding to mask state involvement in disruptive or retaliatory campaigns. It has been cited alongside personas such as Cyber Av3ngers as an example of Iranian-aligned operators using public personas for deniability and influence. Known aliases include DarkBit and DEV-1084.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned ‘hacktivist’ persona used for plausible deniability and psychological impact; associated in this brief with disruptive/destructive activity branding rather than a clearly delineated APT unit.
Ransomware operations, possibly linked to Iranian espionage activities.
Iran-linked threat actor cluster listed in Microsoft's naming taxonomy mapping.
DEV-1084, in partnership with Iranian APTs, conducted destructive attacks disguised as ransomware, targeting Israeli organizations and aiming for destruction and disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.