Cyber Islamic Resistance-Axis is a pro-Iranian, pro-Axis of Resistance hacktivist entity publicly aligned with Iranian and anti-Israel narratives. It has been identified alongside groups such as Conquerors Electronic Army and Cyber Isnaad Front in campaigns framed around regional conflict and information confrontation. The group is associated with the broader surge of pro-Iranian and pro-Palestinian hacktivism that intensified during periods of military escalation involving Iran and Israel. Activity attributed to this milieu is characterized primarily by low-to-medium sophistication disruptive operations, especially distributed denial-of-service attacks and website defacements, with accompanying propaganda and influence messaging. Reporting on the wider campaign environment also notes claims of data breaches and the advertisement or sale of initial access affecting internet-exposed enterprise and operational technology environments, including remote access and industrial control contexts; however, specific advanced tradecraft directly attributable to Cyber Islamic Resistance-Axis is not established at high confidence. The group appears to operate as part of an ideologically motivated hacktivist ecosystem rather than as a clearly documented standalone state unit. Its observed alignment, branding, and targeting patterns are consistent with anti-Israel and anti-Western cyber operations conducted in support of Iranian geopolitical narratives. High-confidence reporting supports classification as a hacktivist actor engaged in disruptive and propaganda-oriented cyber activity, with broader ecosystem overlap involving pro-Iranian threat clusters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.