Also known as: Transparent Tribe, DarkStorm, MRHELL112, Earth Karkaddan, Mythic Leopard, the Handala Hack Team, Storm-0842, Banished Kitten, Temp Zagros, Static Kitten, 313 Team, Cyber Av3ngers, Storm-0784, INC Ransomware
Sylhet Gang‑SG (also known as Transparent Tribe, DarkStorm, MRHELL112, Earth Karkaddan, Mythic Leopard, Handala Hack Team, Storm‑0842, Banished Kitten, Temp Zagros, Static Kitten, 313 Team, Cyber Av3ngers, Storm‑0784, INC Ransomware) presents itself as a volunteer‑based hacktivist front that amplifies pro‑Palestinian messaging while simultaneously conducting destructive cyber operations. The group’s public narrative often claims allegiance with the KillNet 2.0 collective and frames attacks against Western entities as responses to perceived Israeli aggression. The operational history of Sylhet Gang is marked by rapid progression from symbolic defacement and targeted DDoS actions to more lethal supply‑chain penetration. Notably, in February and March 2026 they conducted a coordinated surge of 149 hacktivist‑attributed DDoS attacks on 110 organizations across 16 countries following the U.S.–Israel military campaign against Iran. Their toolkit reflects a hybrid blend of opportunistic phishing techniques plus state‑grade capabilities. Initial access is typically achieved via spear‑phishing with valid credentials harvested from dark‑web leaks or exploiting contemporary headlines; lateral movement frequently leverages hands‑on‑keyboard operations and hijacking of administrative tooling such as Microsoft Intune to enforce remote factory resets. Custom wiper malware – Hatef on Windows and Hamsa on Linux – is delivered through multi‑stage loaders. Additionally, the group is known to deploy backdoors like the Deno‑based Dindoor and Python‑based Fakeset, and sometimes employs commercial infostealers such as Rhadamanthys. Beyond direct sabotage, Sylhet Gang routinely defaces victim web properties and leaks stolen data on its Telegram channel and dark‑web forums, creating a synergy of psychological impact and technical damage. Their focus on critical infrastructures – from the Port of Los Angeles to Rockwell Automation PLCs – demonstrates an intent to disrupt operations in high‑visibility industries while maintaining plausible deniability for state sponsors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Sylhet Gang‑SG, a pro‑Palestinian hacktivist collective linked to Iranian state actors, executes large‑scale DDoS campaigns and destructive wiper malware against critical infrastructure and foreign governments perceived as allies of Israel. Their operations blend politically motivated messaging with technical sabotage, targeting a wide range of sectors including defense, finance, healthcare, telecoms, energy, and industry worldwide. The group’s rapid escalation from symbolic attacks to supply‑chain disruption underscores the significant operational tempo and evolving threat surface.
Goals & Targeting
The primary strategic objective of Sylhet Gang‑SG is political disruption aimed at undermining support for Israel and its Western allies. By targeting government, defense, energy, finance, healthcare, telecoms and industrial sectors across a broad geographic span – including the U.S., UAE, Bahrain, Jordan, Kuwait, Romania, Saudi Arabia, Iran, Israel, Pakistan, India, and Greece – the group seeks to showcase geopolitical grievances through economic and operational sabotage. Their typical victims include state agencies, critical infrastructure operators, large multinational corporations, and any entity that can be positioned as a proxy for Israeli policy. The campaign’s narrative framing and public post‑attack disclosures are designed to galvanize sympathizers and pressure affected entities to reconsider alliances.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Sylhet Gang‑SG demonstrates a pronounced operational tempo, rapidly scaling from symbolic defacement to supply‑chain disruption over a matter of days. Their attack patterns reveal a preference for exploiting current geopolitical events – for instance, capitalizing on the 2024 CrowdStrike outage – and targeting nations aligned with Israel. Notable past operations include large‑scale DDoS assaults on the Port of Los Angeles and various UAE governmental portals in late February 2026, as well as destructive malware campaigns against the medical technology firm Stryker in March 2026 and attacks on Rockwell Automation PLCs attributed to the cluster CL‑STA‑1128. The group’s methodology leverages legitimate credentials when available, sophisticated botnet orchestration for DDoS, and custom-built malwares that combine backdoor persistence with destructive payloads. Their alignment with other Iranian‑affiliated cells (e.g., Handala, DarkStorm) indicates a collaborative ecosystem aimed at maintaining plausible deniability while maximizing impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the documented DDoS activity and spear‑phishing campaigns is high, backed by Unit 42 case studies, CISA advisories, and corroborating reports of recent attacks on prominent entities. Evidence supporting the use of custom wiper malware such as Hatef/Hamsa and backdoors like Dindoor/Fakeset is moderate: these have been observed in triaged samples but lack extensive independent validation across multiple incidents. Attribution details for the numerous aliases remain incomplete; while overlap with Iranian state‑supported cells is plausible, definitive proof of direct state sponsorship or operational integration remains unclear. Missing data include precise deployment timelines, full scope of affected systems, and success metrics (e.g., payload efficacy).
No campaigns linked yet.
No observed data linked yet.
11
Techniques
47
Tools
0
Campaigns
39
IOCs
0
Observed Data
7
Tactics