Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Edalat-e Ali

Description

Edalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as the Revolution Day ceremonies. They have also targeted government facilities, releasing security camera footage to expose abuses and draw attention to human rights violations. The group has used their hacks to call for protests against the Iranian regime and have displayed anti-government messages during their disruptions. Edalat-e Ali has been active in releasing sensitive information and footage to embarrass Iranian officials and highlight injustices within the country.

AI Analysis

· 1 week ago

Executive Summary

Edalat-e Ali is a hacktivist group targeting Iranian state-run media and government facilities to disrupt operations and expose sensitive information, likely seeking regime change and highlighting human rights issues.

Goals & Targeting

The group's goals align with anti-government protests and regime change in伊朗, targeting sectors like media and government to embarrass officials and highlight human rights violations.

Enhanced Description

Edalat-e Ali operates with disruptive tactics against伊朗的国家媒体和政府设施,如在革命日等重要活动期间干扰电视和广播信号,并泄露安全摄像头 footage以揭露 abuses。这些行动旨在通过网络手段推动政治变革,影响国内外舆论,支持国内抗议活动。

Key Capabilities

  • Disruption of state-run media transmissions
  • Data exfiltration and publication of sensitive footage
  • Use of DDoS attacks
  • Website defacements

MITRE ATT&CK Tactics

Disruption
Exfiltration/Leak

ATT&CK Techniques

T1486
T1505.001

Software / Tooling

Custom DDoS tools
Leaks frameworks

Campaigns & Victims

Active during significant events, targeting state-run media and government facilities with disruptive campaigns to influence public perception and domestic protests.

IOC Patterns

  • DDoS attack patterns targeting .ir domains
  • Website defacements on government sites
  • Data leaks from Iranian government networks

Recommended Actions

  • Monitor for DDoS activity against critical systems
  • Enhance web application security
  • Conduct employee training on social engineering
  • Implement robust SIEM for log analysis

Suggested Tags

APT
hacktivism
cyberactivism
Iran
government-sector

Confidence Assessment

Moderate confidence based on known operations; more details on TTPs and tools are needed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
Hacktivism
APT
hacktivism
cyberactivism
Iran
government-sector

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.