313 Team is an Iran-aligned hacktivist group active in the cyber dimension of the regional conflict involving Iran, Israel, and Gulf states. The group has described itself as part of the Cyber Islamic Resistance in Iraq and has been identified alongside other pro-Iranian actors such as Handala Hack, Dark Storm Team, FAD Team, DieNet, Fatimion Cyber Team, and ALTOUFAN TEAM. Available reporting characterizes it as a non-state but politically aligned actor operating for visibility, propaganda value, and support of broader pro-Iranian objectives rather than as a formally acknowledged Iranian state unit. The group is primarily associated with disruptive operations, especially denial-of-service activity against public-facing targets. During the February-March 2026 escalation, 313 Team was among the more active pro-Iranian hacktivist brands by volume of attack claims. Its claimed operations included disruptions affecting government and military services in Bahrain and Kuwait. More broadly, Iran-aligned groups in the same campaign cluster focused on government services, critical infrastructure, and financial institutions across Israel and Gulf states hosting U.S. assets. Assessment of 313 Team’s real-world impact remains cautious. Public reporting indicates that some of its claims are difficult to verify and may have overstated operational effects, with some incidents described as minor disruptions or later attributed elsewhere. This places the group within a wider ecosystem of Telegram-amplified hacktivist activity in which the public claim itself serves psychological, reputational, and signaling purposes. The actor is therefore best understood as a disruptive and propagandistic cyber persona whose main demonstrated capability is short-duration service disruption rather than confirmed deep intrusion or destructive access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned hacktivist group active in Gulf-focused cyber campaigns, initially associated with public disruption operations and attack claims amplified عبر messaging channels.
Iran-aligned hacktivist group known in this content for claiming denial-of-service attacks against Bahrain and Kuwait government and military services, though the real impact and attribution were disputed or unverified.
Named as a pro-Iranian hacktivist group active during the March 2026 escalation, associated with attack claim activity.
Claimed responsibility for operations targeting Israeli and Gulf interests, primarily focusing on critical infrastructure, government services, and financial institutions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.