313 Team, also known as the Islamic Cyber Resistance in Iraq and sometimes styled as UniT 313, is an Iraq-based, pro-Iran hacktivist and resistance-branded disruption actor operating within the broader Iran-aligned cyber proxy ecosystem. The group is widely associated with Iraqi militia-aligned and Axis of Resistance narratives and is assessed as part of a loosely coordinated coalition that uses Telegram for mobilization, propaganda, target selection, and amplification of allied operations. It has been described as a central node in coalition activity alongside other Iran-aligned disruptive actors such as DieNet, Dark Storm Team, Cyber Islamic Resistance, Cyber Fattah, FAD Team, and Conquerors Electronic Army. The group’s activity is dominated by distributed denial-of-service operations, symbolic targeting, propaganda, and coalition amplification rather than advanced intrusion tradecraft. Reported operations include disruptive campaigns against government portals in Jordan, Kuwait, and the United Arab Emirates; attacks against social media and online platforms including Bluesky, Truth Social, Archive.org, and Ubuntu/Canonical infrastructure; and broader multi-country targeting framed as retaliation against states perceived as aligned with the United States or Israel. During the 2026 Iran conflict escalation, 313 Team was repeatedly identified as one of the most active actors by incident volume and participated in coordinated campaigns spanning Gulf government entities and other public-facing services. 313 Team has also been linked to defacement and data-leak claims, though its most consistently corroborated capability is service disruption through DDoS, including use of commercialized DDoS-for-hire infrastructure. In the May 2026 campaign against Canonical and Ubuntu infrastructure, the group claimed responsibility for sustained disruption affecting public-facing services and paired the operation with coercive messaging demanding contact and threatening continued attacks unless its demands were met. This behavior indicates overlap between hacktivist disruption and extortion-style pressure. Reporting consistently characterizes the group’s operational sophistication as relatively low, with effectiveness derived from scale, speed of mobilization, target selection, and psychological impact rather than bespoke malware or stealthy access operations. 313 Team’s targeting pattern centers on government and public-sector entities, symbolic Western or allied online platforms, and organizations associated with U.S., Israeli, or Gulf interests. The group’s public messaging frames operations as retaliation and ideological resistance, aligning with pro-Iranian geopolitical objectives. Its dominant motivation is hacktivism.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Launching disruptive and extortion-oriented attacks against Canonical and Ubuntu infrastructure using a DDoS-for-hire service, causing outages to official websites and Ubuntu’s security API.
Iran-aligned disruption actor using DDoS, propaganda, and symbolic targeting; noted for participation in the May 2026 Canonical/Ubuntu disruption.
Claimed responsibility for a distributed denial-of-service attack against Canonical, disrupting Ubuntu download and update mirrors, the main website, Launchpad, the Snap store, and Canonical SSO.
Pro-Iran hacktivist group conducting sustained DDoS attacks and appearing to shift toward extortion by demanding Canonical contact them or face continued disruption. The group also claimed similar DDoS attacks against eBay Japan, eBay US, and BlueSky.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.