Anonymous Syria Hackers is a Syrian-aligned, pro-Israel counter-hacktivist identity active in conflict-driven cyber propaganda and retaliation campaigns. It has publicly framed Syrian security and sovereignty as a red line and threatened cyber retaliation against perceived adversaries, including disruption of critical digital infrastructure and sensitive electronic systems. The group is associated with anti-Iran operations aimed at Iranian government channels, state-media and propaganda outlets, and infrastructure linked to the Islamic Revolutionary Guard Corps. It has also publicized alleged data breaches involving Iranian organizations; however, the operational impact and technical validity of these claims have not been independently established. The group is also known as ANONYMOUS SYRIA HACKERS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor presenting itself as a Syria-aligned hacktivist group and threatening retaliatory cyberattacks against entities perceived as targeting Syria. Related material attributes a prior alleged compromise of a UAE tourism portal to the group.
Pro-Israel counter-hacktivist group targeting Iranian government, propaganda, and IRGC-linked infrastructure.
Pro-Israel actor conducting breach-and-leak operations against Iranian targets, including educational and e-commerce entities, and publishing stolen credential and personal data claims.
Anti-Iran Syrian opposition-aligned group targeting Iranian state media, government infrastructure, and IRGC-linked entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.