Fatemiyoun Cyber Team is a suspected pro-Iranian, likely IRGC-linked cyber actor that has publicly claimed disruptive and data-leak operations against government targets in the Middle East. Reported activity includes attacks on government and ministry websites in Jordan and Kuwait, as well as the leak of user data associated with a Kuwaiti government application. The group has been described as operating in alignment with broader Iranian strategic objectives, particularly against regional states viewed as aligned with the United States or Israel. Fatemiyoun has also been referenced alongside other pro-Iranian cyber and influence actors active during periods of regional military escalation. Known aliases include Fatemiyoun, fatemiyoun_cyber, and fatemiyoun_cyber_team. Based on the available reporting, the actor’s observed behavior supports assessment of capabilities in initial access, data exfiltration, disruptive website takedowns consistent with denial-of-service activity, and post-compromise operations intended to publicize stolen information. The dominant motivation is assessed as espionage, given the politically aligned targeting and state-linked context, although disruptive and influence-supporting effects are also evident.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor involved in data leaks and website takedowns against government-related targets in Kuwait and Jordan; also described as delivering destructive effects alongside other groups.
Pro-Iranian hacktivist group conducting attacks on government websites in regional states aligned with U.S. and Israeli interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.