313 Team, also known as the Islamic Cyber Resistance in Iraq and the Iraqi Cyber Army, is an Iraq-based, pro-Iran-aligned hacktivist collective operating within the broader Cyber Islamic Resistance ecosystem. Its public messaging combines Iraqi Shia resistance branding, pro-Palestinian themes, and ideological propaganda distributed primarily through Telegram, with supporting social-media, defacement, backup, and leak-oriented channels. The group has been associated with website defacements since at least 2023 and uses coalition messaging, target promotion, and amplification alongside other Iran-aligned hacktivist groups. 313 Team is principally associated with disruptive distributed denial-of-service operations and coercive messaging rather than demonstrated advanced intrusion tradecraft. In 2026, it claimed responsibility for a sustained DDoS attack against Canonical and Ubuntu public services that disrupted Ubuntu.com and related authentication and development services. Canonical confirmed the sustained cross-border DDoS incident. The group subsequently demanded that Canonical establish contact and threatened continued disruption, representing extortion-style coercion paired with service denial. 313 Team has also made numerous public claims of attacks against government, commercial, and online-platform targets, but many of those claims have not been independently verified. The collective has repeatedly promoted purported "313 Ransomware" capabilities, including encryption, data theft, and victim negotiation, but no ransomware sample has been recovered or independently validated. It has also promoted a project called 313 HackBar, although available evidence does not establish that the core operators developed it. The group should therefore be assessed primarily as a resistance-branded disruption and propaganda actor; its claimed ransomware, data-theft, and intrusion capabilities remain unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Third-party group to which BLACKNET-00 reportedly offered its tools.
Hacktivist and claimed ransomware operations combining website defacements, propaganda, leak-channel activity, extortion-style victim messaging, and promotion of a purported '313 Ransomware' capability.
Iraqi-nexus group identified as a prospective or claimed user of TRK-25 ICS/SCADA tooling. Its claimed use of the tool against a US news agency is unverified.
Launching disruptive and extortion-oriented attacks against Canonical and Ubuntu infrastructure using a DDoS-for-hire service, causing outages to official websites and Ubuntu’s security API.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.