Also known as: Shiite_Harvest, MuddyWater, tracked as, Cyber Av3ngers, Storm-0784, DarkStorm, ransomware, MRHELL112, INC Ransomware
DieNet emerged in March 2025 as a politically driven hacktivist collective, proclaiming support for its Shiite affiliates through coordinated attacks on entities tied to political figures. The group’s first noted operations targeted ten Iraqi websites and later a Trump‑aligned business network, utilizing #DieNet and #Shiite_Harvest hashtags to broadcast their intent. Since 2025 DieNet has expanded beyond DDoS, incorporating advanced techniques such as token manipulation, container abuse, and sophisticated Kerberos ticket forgery to gain persistence, evade detection, and achieve lateral movement. The group’s toolkit includes trusted developer utilities (MSBuild, ClickOnce, JamPlus), Docker/Kubernetes orchestration, and a suite of command‑line and script based payloads that support audio/video capture, data encoding, and exfiltration. DieNet demonstrates a clear operational shift toward multi‑vector campaigns: high‑volume Reflection DDoS using large botnets; credential‑reuse tactics (Pass the Hash/Ticket); exploitation of industrial control PLCs from Rockwell Automation/Allen‑Bradley platforms; and an emerging ransomware presence linked to Dark Storm Team / MRHELL112. These capabilities reveal a group ready to adapt tools across multiple environments—cloud, on‑prem, and OT—to maximize impact.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DieNet is an emergent hacktivist group that surfaced in early 2025 and has rapidly escalated from high‑volume DDoS campaigns to multi‑vector attacks targeting critical U.S., Israeli, Australian, and Middle Eastern infrastructure. The actors blend political disruption with sophisticated credential abuse—such as Kerberos golden/silver tickets—and exploit industrial control systems while also deploying ransomware families under the Dark Storm banner.
Goals & Targeting
DieNet’s strategic objectives revolve around political disruption and sectarian messaging. By targeting governments, financial services, energy, telecommunications, healthcare, critical infrastructure, and educational institutions across Israel, Iran, the U.S., Australia, UAE, Turkey, Saudi Arabia, Egypt, Russia, India, Nigeria, and Poland, the group seeks to destabilize state‑backed or politically associated networks while amplifying its ideological narrative. Its selection of high‑profile public services (e.g., national portals, universities) indicates a desire for visibility and propaganda dissemination rather than pure financial gain.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DieNet’s operational tempo has accelerated dramatically, particularly in March 2026 when it executed over 192 separate attacks—a yearly output compressed into a single month. The group has consistently paired large‑scale reflection amplification DDoS with opportunistic defacement campaigns against government ministries, university networks, and consumer brands, especially within Australia and the Middle East. In addition to denial‑of‑service, DieNet performed 12 exfiltration events using command‑and‑control channels, leveraged Pass‑the‑Hash/Ticket techniques for lateral movement, and exploited Rockwell Automation/Allen‑Bradley PLCs through affiliated actors (CL‑STA‑1128/Cyber Av3ngers/Storm‑0784). A ransomware component under the Dark Storm Team / MRHELL112 banner has also emerged, signaling a broadening threat spectrum beyond pure disruption. Victim types span national critical infrastructure, finance, defense, healthcare, and public sector portals in a geographically diverse footprint. Operations are coordinated via social media hashtags while using sophisticated credential abuse to facilitate persistence and exfiltration across cloud and on‑prem environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a high‑level view of DieNet’s tactics, techniques, and objectives based largely on public reports and shared indicators. While the breadth of MITRE technique coverage suggests significant threat actor sophistication, there remain gaps regarding exact attribution timelines, in‑depth technical capabilities (e.g., specific ransomware payloads), and precise adversary infrastructure. The operational tempo and geographic reach are corroborated by multiple sources but the depth of evidence for certain techniques (e.g., Kerberos ticket forging) is largely inferred from associated tool usage rather than confirmed capture samples.
No campaigns linked yet.
No observed data linked yet.
74
Techniques
53
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics