Soldiers of Solomon is an Iranian-linked cyber persona associated with the broader ecosystem of Islamic Revolutionary Guard Corps (IRGC)-aligned operations targeting Israel and, in some reporting, other countries aligned against Iranian interests. It has been described as connected to CyberAv3ngers and tracked by Microsoft under Storm-0784 as one of multiple personas used in campaigns that blend disruptive cyber activity with aggressive information operations and exaggerated public claims. The persona has been used to claim attacks against Israeli military and critical infrastructure targets, and is part of a pattern in which Iranian operators pair limited or opportunistic intrusions with propaganda, defacement, and narrative amplification on social platforms such as Telegram and X. Reporting indicates that at least some claims attributed to Soldiers of Solomon overstated the precision or operational impact of the underlying intrusion. In one documented case, the persona was tied to a ransomware attack while simultaneously making inflated claims about attacks on Israeli military infrastructure. Soldiers of Solomon shares tradecraft and operational themes with other IRGC-linked personas focused on industrial control systems, internet-exposed devices, and psychologically impactful disruption. Across this cluster, operators have used reconnaissance of exposed assets, abuse of default or weak credentials, manipulation of programmable logic controllers and human-machine interfaces, internal defacement, and other disruptive actions intended to create visibility and intimidation disproportionate to the technical sophistication of the intrusion. The persona fits Iran’s broader model of using proxy or hacktivist branding to preserve plausible deniability while supporting retaliation, coercive signaling, and influence objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated IRGC-linked persona mentioned as sharing TTPs and infrastructure with CyberAv3ngers in campaigns against critical infrastructure.
Named hacktivist/proxy group referenced as part of Iran’s broader ecosystem; expected to contribute to increased disruptive activity and narrative signaling.
Persona attributed by Microsoft to the same operator as Cyber Avengers (Storm-0784), focused on compromising IoT/ICS-related devices (e.g., security cameras) and using leaks/claims to intimidate and shape perceptions; includes exaggerated claims (e.g., alleged IAF base camera compromise).
An Iran-linked persona/group name used for information operations on Telegram, claiming attacks (including against Israeli military/critical infrastructure); described as having conducted ransomware but overstating precision and impact.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.