Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors
🇮🇷 IR1 malware family

Cyber Islamic Resistance

Also known ascyber_islamic_resistance

Cyber Islamic Resistance is a pro-Iran, Iranian-affiliated hacktivist umbrella and coordination brand within the broader “Resistance Axis” ecosystem. The content describes it as the active coordination umbrella for pro-Iran hacktivist activity and as the organizer of a joint “Electronic Operations Room” announced on March 1, 2026, reportedly bringing together 15+ groups. Reported affiliated or participating groups include Team 313, Fatimion Cyber Team, Cyber Fattah, DieNet, Sylhet Gang-SG, Moroccan Black Cyber Army, RipperSec, and in some reporting Handala and other aligned elements. Across the cited reporting, Cyber Islamic Resistance is associated primarily with disruptive and symbolic operations including distributed denial-of-service attacks, website defacements, phishing campaigns, reconnaissance, credential theft, data theft, and hack-and-leak activity. It is described as coordinating attacks across Israel, Gulf states, Jordan, Saudi Arabia, Kuwait, Bahrain, Oman, Turkey, Poland, and in some cases U.S.-linked entities. Specific claims attributed to the group in the content include DDoS attacks against an Israeli defense contractor and multiple municipal governments in coordination with NoName057(16); a claimed breach of an Israeli health insurance provider supported by leaked CCTV footage; a claimed hack of Hadassah Ein Kerem Hospital; a claimed breach of Israeli cybersecurity firm MEGINIM DATA SERVICES; and attacks against building management systems in Israel. The content also states that Cyber Islamic Resistance and aligned channels shared screenshots allegedly showing access to OT/ICS-related environments, including VeroPoint industrial control systems, PLC controllers, energy monitoring dashboards, and building management systems. However, multiple reports in the content note that many OT/ICS-related claims by Cyber Islamic Resistance and affiliated actors were unverified or only partially verified. Additional reporting characterizes the group as functioning as an umbrella for disruptive and symbolic operations, while some sources further allege coordinated router compromises and BGP hijack claims against Israeli targets. Overall, the content consistently portrays Cyber Islamic Resistance as a pro-Iran coordination umbrella rather than a single standalone intrusion set, focused on coalition-building, propaganda amplification, and orchestration of low-level to moderately disruptive cyber operations during the 2025–2026 regional conflict period.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Utilities

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics26 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1190×2
Exploit Public-Facing Application
T1566
Phishing
TA0002
Execution
1 technique
T1651
Cloud Administration Command
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
1 technique
T1078
Valid Accounts
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
TA0007
Discovery
1 technique
T1654
Log Enumeration
TA0009
Collection
2 techniques
T1005
Data from Local System
T1560
Archive Collected Data
TA0010
Exfiltration
4 techniques
T1020×2
Automated Exfiltration
T1041
Exfiltration Over C2 Channel
T1537×2
Transfer Data to Cloud Account
T1567×3
Exfiltration Over Web Service
T1567.003
Exfiltration to Text Storage Sites
TA0040
Impact
7 techniques
T1485×4
Data Destruction
T1486
Data Encrypted for Impact
T1489
Service Stop
T1491×2
Defacement
T1491.001×8
Internal Defacement
T1491.002×2
External Defacement
T1498×16
Network Denial of Service
T1561
Disk Wipe
T1565
Data Manipulation
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping24

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.