Iranian Cyber Army is a politically themed threat actor name used in connection with high-profile website takeover and defacement activity, most notably the temporary compromise of Twitter’s DNS records in 2009. In that incident, visitors to Twitter were redirected to a defacement page carrying political messaging and claiming responsibility in the name of the group. Available reporting on the event indicates the redirection was achieved through use of valid credentials associated with Twitter’s DNS management rather than exploitation of a software flaw in the DNS provider. The operation therefore demonstrates at least credential abuse, website redirection, and defacement-oriented post-compromise activity. The actor name is associated in the available evidence with pro-Iranian political messaging and activity occurring in the context of unrest following Iran’s disputed 2009 presidential election, during which Twitter had become an important platform for protest coordination and information sharing. High-confidence facts directly support an Iran nexus in branding and messaging, but do not by themselves establish formal state control or a definitive organizational structure. No corroborated sub-groups or additional aliases are established in the available information beyond the name Iranian Cyber Army.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for compromising Twitter's DNS records and redirecting visitors to a defacement page carrying political messaging tied to Iran.
Claimed responsibility for the Twitter website defacement and DNS hijacking incident, using compromised valid Twitter credentials to redirect the site to a defacement page.
Iranian Cyber Army
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.