MONARCH is a hacktivist brand operating within a broader pro-Iran and Axis-aligned cyber ecosystem characterized by loose coalition behavior, rapid mobilization, propaganda amplification, and disruptive rather than highly sophisticated operations. It has been identified alongside groups such as Fatimiyoun/FAD Team, CJM, Keymous+, and DieNet as contributing attack volume, rhetoric, target-list sharing, and claims amplification in coordinated cyber campaigns tied to geopolitical crises. This ecosystem typically relies on Telegram-based coordination and uses tactics including distributed denial-of-service attacks, website defacements, hack-and-leak claims, credential abuse, doxxing, intimidation, and extortion-style messaging. The broader coalition model emphasizes speed, visibility, deniability, and psychological impact over elite tradecraft, with actors often amplifying one another’s claims and participating in opportunistic targeting of exposed or weakly defended public-facing systems. Within that context, MONARCH is best understood as part of a transnational cyber front that supports wartime or crisis-driven disruption and information effects rather than as a standalone advanced persistent threat. The actor’s activity is associated with targeting patterns seen across government, telecommunications, finance, healthcare, energy, logistics, and other critical infrastructure sectors during periods of regional escalation. Available information supports classifying MONARCH as part of an ideologically aligned hacktivist/proxy network whose dominant function is disruptive operations and narrative amplification in support of pro-Iran geopolitical objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.