Cyber Islamic Resistance
Cyber Islamic Resistance is a pro-Iran, Iranian-affiliated hacktivist umbrella and coordination brand within the broader “Resistance Axis” ecosystem. The content describes it as the active coordination umbrella for pro-Iran hacktivist activity and as the organizer of a joint “Electronic Operations Room” announced on March 1, 2026, reportedly bringing together 15+ groups. Reported affiliated or participating groups include Team 313, Fatimion Cyber Team, Cyber Fattah, DieNet, Sylhet Gang-SG, Moroccan Black Cyber Army, RipperSec, and in some reporting Handala and other aligned elements. Across the cited reporting, Cyber Islamic Resistance is associated primarily with disruptive and symbolic operations including distributed denial-of-service attacks, website defacements, phishing campaigns, reconnaissance, credential theft, data theft, and hack-and-leak activity. It is described as coordinating attacks across Israel, Gulf states, Jordan, Saudi Arabia, Kuwait, Bahrain, Oman, Turkey, Poland, and in some cases U.S.-linked entities. Specific claims attributed to the group in the content include DDoS attacks against an Israeli defense contractor and multiple municipal governments in coordination with NoName057(16); a claimed breach of an Israeli health insurance provider supported by leaked CCTV footage; a claimed hack of Hadassah Ein Kerem Hospital; a claimed breach of Israeli cybersecurity firm MEGINIM DATA SERVICES; and attacks against building management systems in Israel. The content also states that Cyber Islamic Resistance and aligned channels shared screenshots allegedly showing access to OT/ICS-related environments, including VeroPoint industrial control systems, PLC controllers, energy monitoring dashboards, and building management systems. However, multiple reports in the content note that many OT/ICS-related claims by Cyber Islamic Resistance and affiliated actors were unverified or only partially verified. Additional reporting characterizes the group as functioning as an umbrella for disruptive and symbolic operations, while some sources further allege coordinated router compromises and BGP hijack claims against Israeli targets. Overall, the content consistently portrays Cyber Islamic Resistance as a pro-Iran coordination umbrella rather than a single standalone intrusion set, focused on coalition-building, propaganda amplification, and orchestration of low-level to moderately disruptive cyber operations during the 2025–2026 regional conflict period.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Utilities
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Umbrella hacktivist coordinator directing joint operations across Gulf states and Israel through a multi-group operations room.
Early hacktivist mobilization linked to the opening cyber phase of the Iran war.
Claimed attacks against building management systems in Israel, including disruptive operations affecting hotel doors, electricity, water, and lighting networks.
Pro-Iranian collective claiming retaliatory cyber operations against Israeli and Western targets across critical sectors.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.