Fatimiyoun/FAD Team is an Iran-aligned hacktivist or proxy-style cyber persona associated with the broader Axis-aligned online disruption ecosystem. It is described as part of a loose, deniable mobilization network rather than a traditional advanced persistent threat, operating alongside brands such as Handala, 313 Team, Cyber Islamic Resistance, Dark Storm, CJM, Keymous+, DieNet, MONARCH, and Killnet to project the image of a broad transnational cyber front. This ecosystem uses shared propaganda, repeated disruption, leak operations, and anti-Western or anti-Israel messaging to create cumulative operational and psychological pressure during periods of geopolitical escalation. The actor is associated with common hacktivist tradecraft including distributed denial-of-service activity, website defacement, hack-and-leak style claims, credential abuse, doxxing, intimidation, and propaganda amplification through social channels such as Telegram. Within the wider Iran-aligned ecosystem, these operations are characterized by rapid mobilization around crises, symbolic targeting, public claims of impact, and narrative shaping rather than elite or highly bespoke intrusion tradecraft. The broader ecosystem has been assessed as capable of targeting government, financial, telecommunications, healthcare, energy, logistics, and critical infrastructure organizations, with government institutions particularly prominent during regional escalations. Fatimiyoun/FAD Team should be understood as part of a layered Iran-aligned cyber influence and disruption environment that blends hacktivist branding, ideological cyber militias, propaganda actors, criminal-adjacent elements, and state-adjacent influence nodes. Its dominant role appears to be participation in disruptive and psychological operations that amplify regional conflict narratives and impose reputational and operational costs on adversaries.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.