Stucx Team, also styled as stucx or STUCX TEAM 🕷, is a pro-Iran-aligned hacktivist actor associated with cyber activity framed around the Israel-Palestine conflict. Its branding appears intentionally ideological, with the name invoking a revenge reference to Stuxnet and aligning with Tehran’s broader military-industrial narrative. The group has been identified among globally distributed hacktivist ecosystems that support Iranian interests through deniable, low-cost cyber operations rather than through clearly attributable state-directed intrusions. The actor has been linked to claims of access to Israeli water-sector SCADA devices, specifically involving water and wastewater organizations. Those claims elevated concern because of the potential for critical infrastructure impact, but available technical evidence did not confirm that a successful compromise occurred. Broader activity associated with the surrounding hacktivist milieu has centered on low-sophistication disruptive and propaganda-oriented operations, including DDoS activity, website defacement claims, and circulation of allegedly stolen data. In this context, Stucx Team is best characterized as an ideologically motivated hacktivist entity focused on anti-Israel targeting and psychological or reputational impact, with reported interest in critical infrastructure and possible reconnaissance against such targets. The group has been associated with pro-Iranian cyber coalitions that include actors from Indonesia and Malaysia and is part of a wider ecosystem of proxy and sympathizer groups used to amplify regional cyber campaigns while preserving deniability. High-confidence reporting supports ideological alignment with Tehran, but does not establish Stucx Team as a confirmed Iranian state APT or as a verified operator of successful destructive or ICS-disruptive intrusions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Palestinian hacktivist group claiming access to Israeli water systems' SCADA devices amid Gaza conflict-related cyber activity; broader activity described as generally low-sophistication and low-impact, with claims including DDoS attacks, website defacements, and purported data theft.
Pro-Iran group whose branding explicitly references revenge for Stuxnet and signals ideological alignment with Tehran.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.