Cyber Fattah is a pro-Iranian hacktivist group active in Middle Eastern cyber conflict and aligned with the broader Axis of Resistance-style ecosystem of Iranian state-linked proxies, militias, and online influence actors. The group presents itself as an Iranian cyber team and is commonly associated with other resistance-branded collectives including Cyber Fattah Team, 313 Team, Fatimiyoun/FAD Team, Cyber Islamic Resistance, DieNet, and related Telegram-based coalitions. Reporting places Cyber Fattah within Iran’s layered cyber proxy structure, including references to IRGC-linked operational groupings and to disruptive activity conducted by actors aligned with Tehran’s military and ideological narrative. Cyber Fattah has been linked to disruptive and coercive operations against Israeli infrastructure and other regional targets, as well as anti-Saudi and anti-Western activity. Observed targeting includes Israeli infrastructure, educational institutions, media entities, and broader government-related or civilian-facing services, alongside alleged publication of personal records tied to the Saudi Games. Regional reporting also places the group among Iranian-aligned actors active against Gulf states, Jordan, Egypt, Iraq, and U.S.-linked interests during periods of military escalation. The group’s tradecraft is consistent with the broader pro-Iran hacktivist ecosystem: reconnaissance, scanning for exposed internet-facing systems and IoT devices, distributed denial-of-service attacks, website defacements, data theft, leak claims, propaganda amplification, and intimidation messaging. Cyber Fattah has also been cited as using Telegram to rally participants, announce targets, and amplify coalition narratives. In at least one reported case, the group claimed exploitation of CVE-2025-55182 to gain initial access and deploy the BQTlock ransomware, indicating overlap between hacktivist operations and ideologically aligned ransomware activity. Cyber Fattah is best understood as part of a loosely coordinated but operationally useful pro-Iran mobilization network rather than a traditional advanced persistent threat. Its significance lies less in elite tradecraft than in rapid activation during geopolitical crises, coalition participation, psychological pressure, and the ability to contribute attack volume, target selection, and narrative warfare in support of Iranian strategic objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
1 more CVE tied to this actor tracked in Mallory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an aligned resistance-branded group within the broader pro-Iran cyber coalition.
Hacktivist actor contributing attack volume and propaganda amplification within the pro-Iran ecosystem.
Hacktivist group described as activated by Iran following the U.S.-Israel attacks.
Iranian-aligned hacktivist group participating in coordinated cyber activity during the 2026 Iran conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.