Islamic Cyber Resistance in Iraq 313, also known as ICR-313 and The Islamic Cyber Resistance in Iraq 313 Team, is a pro–Axis of Resistance hacktivist persona assessed to operate primarily as a hybrid hack-and-leak and information operations front rather than a sophisticated intrusion set. The group is ideologically aligned with Iran-backed Iraqi militia ecosystems and has been associated in reporting with networks within or adjacent to the Popular Mobilization Forces, while direct state control has not been confirmed. Its branding and messaging are overtly Islamist and Shi’a symbolic, and its operations are framed around retaliation, deterrence, and political signaling tied to regional geopolitical events. ICR-313 has claimed disruptive and publicity-oriented operations against Western, Israeli, and Gulf-linked targets, including major technology platforms and open-source infrastructure providers. Reported target sets include Israeli civilian and government-linked entities, U.S. defense-adjacent organizations, and Gulf energy and infrastructure sectors. The actor appears to prioritize symbolic, reputational, and psychological impact over sustained operational access or destructive cyber effects. Observed and claimed tradecraft includes distributed denial-of-service attacks, website defacement, hack-and-leak activity, data exfiltration, and exposure of stolen credentials or datasets. The group commonly uses selective disclosures, screenshots, sample records, and threats of larger leaks to support its narratives, with Telegram serving as a primary dissemination channel and amplification point. Its campaigns are further propagated through aligned media and social media ecosystems, indicating a strong influence-operations component. Available reporting characterizes ICR-313 as a low-to-moderate capability actor that likely relies on commodity tooling, reused or publicly available data, exposed services, credential reuse, and password spraying rather than custom malware, zero-day exploitation, or long-term persistence. There is no high-confidence evidence that the group operates bespoke malware frameworks, maintains durable access after compromise, or possesses cyber-physical or ICS/OT attack capability. Its risk profile is therefore centered more on disruption, reputational harm, and narrative manipulation than on advanced espionage or destructive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for a DDoS attack disrupting Spotify services and was also described as conducting a similar DDoS attack against Canonical's web infrastructure and services.
Pro-Iran hacking collective claiming responsibility for disruptive DDoS attacks against Western companies and services, including Spotify and Canonical.
Claimed responsibility for a coordinated DDoS attack disrupting Canonical and Ubuntu web infrastructure, including developer portals and Ubuntu security API services. The group is described as an Islamist hacktivist actor conducting politically motivated attacks against Western and technology-linked targets.
Claimed responsibility for a DDoS attack against Ubuntu and Canonical public-facing infrastructure, disrupting websites, the security API, and package update/install functionality.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.