Pyroxene is an OT-focused threat group linked to Iran and assessed to overlap with activity attributed to Imperial Kitten, also known as APT35, which is associated with the Islamic Revolutionary Guard Corps (IRGC). The group has been observed conducting supply chain-leveraged and social-engineering-enabled intrusions against defense, critical infrastructure, and broader industrial targets. Reporting places its activity initially in the Middle East and later expanding into North America and Western Europe. Pyroxene’s operations indicate a focus on gaining access through third-party or supply-chain relationships and then pursuing follow-on intrusion activity in industrial environments. The group has been associated with movement from IT environments toward OT networks, including use of access provided by another actor, PARISITE, to facilitate deeper intrusion into operational environments. Pyroxene has also been tied to deployment of data-wiping malware against organizations in Israel, indicating capability and intent consistent with disruptive or destructive operations rather than purely intelligence collection. Known aliases and overlaps include Pyroxene and activity overlapping Imperial Kitten / APT35. Within OT threat tracking, Pyroxene is notable as one of the newer groups identified as targeting industrial and critical-infrastructure environments, combining supply-chain compromise, social engineering, and destructive malware deployment in support of Iranian state-linked objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain-leveraged intrusions against defense/critical infrastructure/industrial targets, with an IT-to-OT pivot enabled by initial access; overlaps with activity attributed to Imperial Kitten.
Iran-linked (IRGC-associated) cluster conducting supply-chain attacks enabled by social engineering and deploying data-wiping malware against Israeli organizations.
Named by Dragos as a newly identified (2025) threat group targeting OT environments; no additional activity details provided in the content.
Iran-aligned cluster conducting supply-chain-leveraged operations against defense/critical infrastructure/industrial targets, using recruitment-themed social engineering to deliver backdoors and other malware; also associated with data-wiping activity in Israel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.