Laneh Dark is a pro-Iran hacktivist or Iran-aligned cyber actor assessed to participate in anti-Israel and anti-Western operations. It has been described as part of the broader Iranian proxy and hacktivist ecosystem that blends ideological messaging with activity consistent with state-aligned cyber campaigns, although no official government affiliation is established at high confidence. Reported associations include alignment with the Nest Security Group and cooperation with other ideologically aligned actors, including NoName057(16). Laneh Dark has been linked to data theft and ransom-style coercive pressure, and has been associated with claimed targeting of energy-related infrastructure in Israel during the 2025 Israel-Iran conflict. Broader reporting on the Iranian-aligned hacktivist milieu places such groups in campaigns involving reconnaissance, disruptive operations, website defacement, distributed denial-of-service activity, data theft, and attacks against industrial control and operational technology environments. Laneh Dark is best understood as an Iran-supporting threat actor operating in the gray zone between hacktivism and proxy cyber operations, with behavior suggesting politically motivated disruptive and coercive activity rather than conventional cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an Iranian or Iran-supporting hacktivist group posing a threat to the United States and its allies, though not officially affiliated with the Iranian government in the content.
Pro-Iran hacktivist/extortion actor using data theft and coercive leak tactics; targets regional states and claims large-scale access via a named vulnerability; participates in broader alliance structures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.