Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SYLHET GANG-SG

Also known as: Transparent Tribe, DarkStorm, MRHELL112, Earth Karkaddan, Mythic Leopard, the Handala Hack Team, Storm-0842, Banished Kitten, Temp Zagros, Static Kitten, 313 Team, Cyber Av3ngers, Storm-0784, INC Ransomware

Description

Sylhet Gang‑SG (also known as Transparent Tribe, DarkStorm, MRHELL112, Earth Karkaddan, Mythic Leopard, Handala Hack Team, Storm‑0842, Banished Kitten, Temp Zagros, Static Kitten, 313 Team, Cyber Av3ngers, Storm‑0784, INC Ransomware) presents itself as a volunteer‑based hacktivist front that amplifies pro‑Palestinian messaging while simultaneously conducting destructive cyber operations. The group’s public narrative often claims allegiance with the KillNet 2.0 collective and frames attacks against Western entities as responses to perceived Israeli aggression. The operational history of Sylhet Gang is marked by rapid progression from symbolic defacement and targeted DDoS actions to more lethal supply‑chain penetration. Notably, in February and March 2026 they conducted a coordinated surge of 149 hacktivist‑attributed DDoS attacks on 110 organizations across 16 countries following the U.S.–Israel military campaign against Iran. Their toolkit reflects a hybrid blend of opportunistic phishing techniques plus state‑grade capabilities. Initial access is typically achieved via spear‑phishing with valid credentials harvested from dark‑web leaks or exploiting contemporary headlines; lateral movement frequently leverages hands‑on‑keyboard operations and hijacking of administrative tooling such as Microsoft Intune to enforce remote factory resets. Custom wiper malware – Hatef on Windows and Hamsa on Linux – is delivered through multi‑stage loaders. Additionally, the group is known to deploy backdoors like the Deno‑based Dindoor and Python‑based Fakeset, and sometimes employs commercial infostealers such as Rhadamanthys. Beyond direct sabotage, Sylhet Gang routinely defaces victim web properties and leaks stolen data on its Telegram channel and dark‑web forums, creating a synergy of psychological impact and technical damage. Their focus on critical infrastructures – from the Port of Los Angeles to Rockwell Automation PLCs – demonstrates an intent to disrupt operations in high‑visibility industries while maintaining plausible deniability for state sponsors.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Healthcare
Telecommunications
Critical infrastructure
Energy
Manufacturing
Education
Aviation
Aerospace
Non profit
Media

Targeted Countries / Regions

IR
IN
AE
IL
PK
US
SA
IQ
RU
GB

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Sylhet Gang‑SG, a pro‑Palestinian hacktivist collective linked to Iranian state actors, executes large‑scale DDoS campaigns and destructive wiper malware against critical infrastructure and foreign governments perceived as allies of Israel. Their operations blend politically motivated messaging with technical sabotage, targeting a wide range of sectors including defense, finance, healthcare, telecoms, energy, and industry worldwide. The group’s rapid escalation from symbolic attacks to supply‑chain disruption underscores the significant operational tempo and evolving threat surface.

Goals & Targeting

The primary strategic objective of Sylhet Gang‑SG is political disruption aimed at undermining support for Israel and its Western allies. By targeting government, defense, energy, finance, healthcare, telecoms and industrial sectors across a broad geographic span – including the U.S., UAE, Bahrain, Jordan, Kuwait, Romania, Saudi Arabia, Iran, Israel, Pakistan, India, and Greece – the group seeks to showcase geopolitical grievances through economic and operational sabotage. Their typical victims include state agencies, critical infrastructure operators, large multinational corporations, and any entity that can be positioned as a proxy for Israeli policy. The campaign’s narrative framing and public post‑attack disclosures are designed to galvanize sympathizers and pressure affected entities to reconsider alliances.

Enhanced Description

Key Capabilities

  • Large-scale Distributed Denial‑of‑Service (DDoS) campaigns
  • Custom wiper malware (Hatef, Hamsa) capable of full system wipe
  • Stealthy backdoor delivery (Dindoor Deno runtime, Fakeset Python)
  • Credential exploitation via spear‑phishing and dark‑web leaks
  • Lateral movement through administrative tool hijacking (Microsoft Intune, remote factory resets)
  • Defacement and data leak operations on Telegram and dark‑web channels
  • Targeted attacks against OT/ICS equipment (Rockwell Automation, Allen‑Bradley PLCs)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Command and Control
Impact

ATT&CK Techniques

T1566.001
T1566.002
T1078
T1059.003
T1498.002
T1485
T1105
T1021.004
T1086
T1064

Software / Tooling

Dindoor (Deno‑based backdoor)
Fakeset (Python backdoor)
Hatef (Windows wiper)
Hamsa (Linux wiper)
Rhadamanthys (infostealer)
Custom multi‑stage loaders
PowerShell scripts used for lateral movement

Campaigns & Victims

Sylhet Gang‑SG demonstrates a pronounced operational tempo, rapidly scaling from symbolic defacement to supply‑chain disruption over a matter of days. Their attack patterns reveal a preference for exploiting current geopolitical events – for instance, capitalizing on the 2024 CrowdStrike outage – and targeting nations aligned with Israel. Notable past operations include large‑scale DDoS assaults on the Port of Los Angeles and various UAE governmental portals in late February 2026, as well as destructive malware campaigns against the medical technology firm Stryker in March 2026 and attacks on Rockwell Automation PLCs attributed to the cluster CL‑STA‑1128. The group’s methodology leverages legitimate credentials when available, sophisticated botnet orchestration for DDoS, and custom-built malwares that combine backdoor persistence with destructive payloads. Their alignment with other Iranian‑affiliated cells (e.g., Handala, DarkStorm) indicates a collaborative ecosystem aimed at maintaining plausible deniability while maximizing impact.

IOC Patterns

  • Spearfishing emails bearing malicious attachments or links tied to domains such as trumpvsirancoin.xyz or emiratesinvestunion.com
  • Large‑volume outbound DNS traffic originating from previously unseen IP ranges used for DDoS amplification
  • Executable binaries with names like hatef.exe, hamsa.sh, dindoor.dll exhibiting SHA‑256 hashes identical to those observed in the cluster
  • Unusual PowerShell execution chains targeting remote machine management tools (Microsoft Intune)
  • Outbound HTTP/HTTPS traffic toward dark‑web drop‑points or Telegram API endpoints for data exfiltration

Recommended Actions

  • Implement mandatory multi‑factor authentication, especially on privileged and administrative accounts; enforce strong password hygiene and monitor for credential reuse across services.
  • Deploy advanced DDoS mitigation solutions and set threshold alerts for sudden traffic surges that deviate from typical baselines.
  • Enable PowerShell logging with execution validation to detect anomalous use or lateral movement techniques.
  • Implement web filtering and endpoint detection to block spear‑phishing attachments and suspicious URLs; conduct regular phishing simulation training.
  • Maintain isolated, redundant backups of critical systems and verify integrity of backup data via hash checks and offline storage to counter wiper attacks.
  • Introduce network segmentation between corporate LAN and OT/ICS infrastructure, enforce least privilege on PLC access, and implement stringent monitoring for unauthorized configuration changes or remote reset commands.
  • Apply timely patches for known vulnerabilities in operational tools such as Microsoft Intune, Cisco AnyConnect, and relevant OT protocols; conduct periodic vulnerability scanning of all critical assets.
  • Establish incident response playbooks that include containment procedures for backdoor execution (Dindoor, Fakeset) and immediate system isolation following detection of destructive malware signatures.

Suggested Tags

APT
Hacktivist
Pro‑Palestinian
Iran‑affiliated
Political sabotage
Disruption
DDoS actor
Custom wiper malware
Industrial Control System threat
Supply‑chain sabotage
Targeted sectors: Government, Defense, Critical Infrastructure

Confidence Assessment

The confidence in the documented DDoS activity and spear‑phishing campaigns is high, backed by Unit 42 case studies, CISA advisories, and corroborating reports of recent attacks on prominent entities. Evidence supporting the use of custom wiper malware such as Hatef/Hamsa and backdoors like Dindoor/Fakeset is moderate: these have been observed in triaged samples but lack extensive independent validation across multiple incidents. Attribution details for the numerous aliases remain incomplete; while overlap with Iranian state‑supported cells is plausible, definitive proof of direct state sponsorship or operational integration remains unclear. Missing data include precise deployment timelines, full scope of affected systems, and success metrics (e.g., payload efficacy).

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 12 Domain 5 Filename 1 URL 2

References

  1. blog.talosintelligence.com — Cited by web research for: the Handala Hack Team
  2. unit42.paloaltonetworks.com — Cited by web research for: Cyber Av3ngers
  3. www.infosecurity-magazine.com — Cited by web research for: Crimson RAT

Intel Summary

11

Techniques

47

Tools

0

Campaigns

39

IOCs

0

Observed Data

7

Tactics

Tags

Critical Infrastructure
DDoS
Government Targeting
Hacktivism
Hacktivist
Political-motivated
APT
Pro‑Palestinian
Iran‑affiliated
Political sabotage
Disruption
DDoS actor
Custom wiper malware
Industrial Control System threat
Supply‑chain sabotage
Targeted sectors: Government, Defense, Critical Infrastructure

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.