Also known as: DarkStorm, 313 Team Hack Team, Islamic Cyber Resistance, Earth Bluecrow, DecisiveArchitect, Red Dev 18, the Handala Hack Team, Storm-0842, Banished Kitten, Temp Zagros, Static Kitten, Cyber Av3ngers, Storm-0784, ransomware, Void Manticore, Earth Preta, TA416, DeadCatx3, PCPcat, DUNE, Red Sandstorm, MRHELL112, INC Ransomware, Bronze President, ShellForce
313 Team operates as a front for Iran‑aligned cyber activity, leveraging publicly available tooling from GitHub and other open‑source repositories to orchestrate attacks that are both politically motivated and financially opportunistic. It routinely launches large‑scale volumetric DDoS assaults targeting high‑profile government sites, cloud services, and software distribution platforms, often announcing results on Telegram channels for propaganda value. When defensive suppression fails, the actor escalates to destructive wiper operations—custom malware such as Hatef (Windows) and Hamsa (Linux) are delivered through multi‑stage NSIS or PowerShell chains that later spread via lateral movement using Microsoft Intune’s factory‑reset feature. The group also exploits supply‑chain vulnerabilities by tampering with Trivy Docker images and GitHub releases, embedding persistent backdoors like Dindoor (Denon runtime) and Fakeset (Python) to maintain command‑and‑control over HTTP/HTTPS or Telegram bot channels. Beyond sabotage, 313 Team extends into industrial control system (ICS) domains, manipulating Hikvision surveillance cameras for reconnaissance and attempting PLC exploitation with Seedworm loaders in addition to Intune integration. This diversified toolkit demonstrates a capacity to compromise both public‑facing web components and critical infrastructure while maintaining low detection profiles through legitimate SaaS channels and commercial cloud storage back‑ends. The actor’s operational cadence is tightly aligned with geopolitical developments, deploying attacks within days of regional tensions rising, demanding ransom in cryptocurrencies for campaign cessation, and issuing high‑visibility statements on social feeds to galvanize activist audiences.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
313 Team, also known by names such as Islamic Cyber Resistance and DarkStorm, is a pro‑Iranian threat actor that blends hack‑and‑leak tactics with political defacement and destructive wiper campaigns. The group frequently launches high‑volume DDoS attacks against government portals, followed by spear‑phishing or credential harvesting to gain valid accounts and deploy custom malware. Publicly claiming responsibility through Telegram, it demands cryptocurrency payments for cessation of its disruptive operations.
Goals & Targeting
313 Team seeks disruption of political stakeholders aligned at odds with Iranian interests, primarily targeting state, defense, financial, healthcare, energy, telecommunications, media, and critical infrastructure sectors across the Middle East, U.S., Russia, and other regions. The group blends sabotage—via DDoS or wiper deployments—with propaganda, executing defacement campaigns that embed coalition imagery to elevate political messaging. By acquiring valid credentials through spear‑phishing or leaked data, the actor gains persistence within corporate environments, facilitating future destructive operations or information exfiltration from compromised cloud services and IoT devices.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
313 Team’s campaigns exhibit a rapid, high‑tempo pattern closely tied to geopolitical events. The actor publicly boasts successes on Telegram and demands cryptocurrency ransoms for campaign cessation. In addition to disruptive DDoS blasts against political targets, the group deploys wiper malware after initial infiltration or as a secondary destructive measure. Supply‑chain exploitation—particularly tampering with public Docker images and GitHub releases—and persistence via backdoor implants indicate an evolution toward more sustained footholds, while its foray into PLC manipulation signals potential future attacks on industrial control systems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information derives from publicly documented incidents and open‑source intelligence, providing a high confidence level regarding the actor’s TTPs and campaign patterns. However, gaps remain around internal attribution certainty, precise operational tempo over time, full sophistication assessment, and undisclosed internal toolchains or infrastructure details.
No campaigns linked yet.
No observed data linked yet.
34
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics