Cyber Isnaad Front is an Iran-linked, state-directed cyber persona active in the pro-Iranian cyber ecosystem that emerged prominently during the 2026 Iran-Israel conflict. The actor is associated with targeting Israeli interests, especially critical infrastructure and strategically sensitive civilian sectors, and has been described as focusing on defense, telecommunications, fuel and transport logistics, and food production. It has also been used as a psychological-pressure and intimidation vehicle through the publication of target lists, threats against critical infrastructure, and propaganda-oriented messaging. The group is notable for activity against Israeli operational technology and industrial environments. In May 2026, it was attributed with sabotaging an Israeli industrial refrigeration system by reprogramming the environment in a way that caused physical equipment failure. Reporting on that incident indicates the operator changed controller credentials, locked out legitimate operators, and manipulated industrial process settings with sufficient domain knowledge to produce destructive effects, distinguishing the operation from more superficial or purely symbolic OT intrusions. Cyber Isnaad Front has also been linked to claimed breaches involving Israeli telecommunications and fuel logistics infrastructure and to the publication of stolen data claims intended to amplify coercive pressure. Within the broader pro-Iran coalition, Cyber Isnaad Front appears less associated with high-volume DDoS operations than with intimidation, target signaling, hack-and-leak style claims, and disruptive or destructive targeting of infrastructure. It has been mentioned alongside other Iran-aligned actors and resistance-branded groups that coordinate and amplify operations through shared messaging channels. High-confidence reporting characterizes it as an Iranian state-directed persona rather than an independent criminal enterprise. Known aliases in the available reporting are limited to Cyber Isnaad Front.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed with a sabotage campaign against Israeli industrial organizations, including a food producer’s refrigeration system, involving manipulation of industrial controller settings and credential changes to lock operators out.
Contributes psychological pressure through target lists, intimidation campaigns, and threats against critical infrastructure.
IRGC-backed cyber persona attributed with sabotage of an Israeli industrial refrigeration system, reflecting focus on industrial operations and supply-chain/logistics targets.
IRGC-backed cyber persona attributed with sabotaging an Israeli industrial refrigeration system, reflecting focus on supply chains, logistics, industrial operations, and food production.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.