Ashiyane Digital Security Team (ADST) is a well-known Iranian security and hacking group that has been associated with website defacement activity and has appeared in reporting connected to broader Iranian cyber activity. The group has been linked through forum moderation, tooling, and community ties to Iranian malware-development and offensive-security circles, including individuals associated with Persian-language crypters and remote-access malware packaging. ADST is notable less as a single publicly documented intrusion set than as a recognizable Iranian hacking collective and ecosystem node whose members or associates have intersected with malware operations and influence within Iranian underground and semi-public security forums. High-confidence reporting ties the group to Iran, but the available information here does not directly establish a distinct, fully attributed espionage or ransomware campaign conducted by ADST itself beyond its role as an Iranian hacking group with prolific defacement activity and connections to Iranian cyber operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.