Unified Islamic Cyber Resistance is a pro-Iranian hacktivist entity active in the Iran-Israel cyber conflict and associated with operations against Israeli infrastructure. It has been publicly associated with attacks on industrial control systems, including activity targeting electric-vehicle fleet-management infrastructure. The group appears within a broader ecosystem of ideologically aligned anti-Israel hacktivist operations that, during mid-2025, emphasized disruptive and propagandistic effects over sustained technical sophistication. Available reporting places the group among actors involved in attacks against Israeli critical infrastructure during the June 2025 escalation. High-confidence information supports its alignment with pro-Iranian hacktivist activity and its involvement in ICS-related targeting, but does not establish a broader verified operational profile, malware lineage, or formal state control. Its apparent motivation is ideological and geopolitical rather than financial.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.