Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors 313 Team

Also known as: DarkStorm, 313 Team Hack Team, Islamic Cyber Resistance, Earth Bluecrow, DecisiveArchitect, Red Dev 18, the Handala Hack Team, Storm-0842, Banished Kitten, Temp Zagros, Static Kitten, Cyber Av3ngers, Storm-0784, ransomware, Void Manticore, Earth Preta, TA416, DeadCatx3, PCPcat, DUNE, Red Sandstorm, MRHELL112, INC Ransomware, Bronze President, ShellForce

Description

313 Team operates as a front for Iran‑aligned cyber activity, leveraging publicly available tooling from GitHub and other open‑source repositories to orchestrate attacks that are both politically motivated and financially opportunistic. It routinely launches large‑scale volumetric DDoS assaults targeting high‑profile government sites, cloud services, and software distribution platforms, often announcing results on Telegram channels for propaganda value. When defensive suppression fails, the actor escalates to destructive wiper operations—custom malware such as Hatef (Windows) and Hamsa (Linux) are delivered through multi‑stage NSIS or PowerShell chains that later spread via lateral movement using Microsoft Intune’s factory‑reset feature. The group also exploits supply‑chain vulnerabilities by tampering with Trivy Docker images and GitHub releases, embedding persistent backdoors like Dindoor (Denon runtime) and Fakeset (Python) to maintain command‑and‑control over HTTP/HTTPS or Telegram bot channels. Beyond sabotage, 313 Team extends into industrial control system (ICS) domains, manipulating Hikvision surveillance cameras for reconnaissance and attempting PLC exploitation with Seedworm loaders in addition to Intune integration. This diversified toolkit demonstrates a capacity to compromise both public‑facing web components and critical infrastructure while maintaining low detection profiles through legitimate SaaS channels and commercial cloud storage back‑ends. The actor’s operational cadence is tightly aligned with geopolitical developments, deploying attacks within days of regional tensions rising, demanding ransom in cryptocurrencies for campaign cessation, and issuing high‑visibility statements on social feeds to galvanize activist audiences.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Healthcare
Energy
Telecommunications
Media
Manufacturing
Critical infrastructure
Non profit
Education
Nuclear
Information technology
Aerospace
Transportation
Pharmaceutical
Utilities
Aviation
Oil gas
Construction
Think tank

Targeted Countries / Regions

IR
IL
US
IQ
AE
SA
UA
RU
LB
CN
TR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 9 hours ago

Executive Summary

313 Team, also known by names such as Islamic Cyber Resistance and DarkStorm, is a pro‑Iranian threat actor that blends hack‑and‑leak tactics with political defacement and destructive wiper campaigns. The group frequently launches high‑volume DDoS attacks against government portals, followed by spear‑phishing or credential harvesting to gain valid accounts and deploy custom malware. Publicly claiming responsibility through Telegram, it demands cryptocurrency payments for cessation of its disruptive operations.

Goals & Targeting

313 Team seeks disruption of political stakeholders aligned at odds with Iranian interests, primarily targeting state, defense, financial, healthcare, energy, telecommunications, media, and critical infrastructure sectors across the Middle East, U.S., Russia, and other regions. The group blends sabotage—via DDoS or wiper deployments—with propaganda, executing defacement campaigns that embed coalition imagery to elevate political messaging. By acquiring valid credentials through spear‑phishing or leaked data, the actor gains persistence within corporate environments, facilitating future destructive operations or information exfiltration from compromised cloud services and IoT devices.

Enhanced Description

Key Capabilities

  • Spearfishing‑based initial access leveraging legitimate accounts
  • Lateral movement via Microsoft Intune factory reset on corporate PCs
  • Custom wiper malware deployment (Hatef for Windows, Hamsa for Linux)
  • Persistent backdoor implants (Dindoor in Deno, Fakeset in Python)
  • Large‑scale volumetric DDoS attacks against government portals and cloud services
  • Supply‑chain compromise of Trivy Docker images and GitHub releases to deploy backdoors
  • Industrial Control System exploitation including PLC manipulation and Hikvision camera abuse for recon
  • Web site defacement with political branding using coalition imagery
  • Infrastructure provisioned via commercial cloud storage (Wasabi, Backblaze) with Rclone-based data exfiltration
  • Telegram‑based command & control channels

MITRE ATT&CK Tactics

Initial Access
Execution
Lateral Movement
Persistence
Credential Access
Defense Evasion
Impact

ATT&CK Techniques

T1005
T1053
T1059
T1071.001
T1071.004
T1078
T1078.004
T1105
T1110.003
T1113
T1189
T1190
T1491
T1491.002
T1498
T1499
T1530
T1561
T1565
T1566.001
T1566.002
T1583
T1585
T1588
T1595
T1598

Software / Tooling

Hatef
Hamsa
Dindoor
Fakeset
Rclone
NSIS installer
PowerShell
Intune
Telegram bot
GitHub repository deployments
Spear‑phishing toolkit

Campaigns & Victims

313 Team’s campaigns exhibit a rapid, high‑tempo pattern closely tied to geopolitical events. The actor publicly boasts successes on Telegram and demands cryptocurrency ransoms for campaign cessation. In addition to disruptive DDoS blasts against political targets, the group deploys wiper malware after initial infiltration or as a secondary destructive measure. Supply‑chain exploitation—particularly tampering with public Docker images and GitHub releases—and persistence via backdoor implants indicate an evolution toward more sustained footholds, while its foray into PLC manipulation signals potential future attacks on industrial control systems.

IOC Patterns

  • domain
  • url

Recommended Actions

  • Implement and harden anti‑DDoS solutions across critical infrastructure and public-facing services.
  • Enhance security awareness training and MFA to mitigate spear‑phishing targeting valid credentials.
  • Deploy monitoring for unusual Intune or MDM factory‑reset commands and enforce least privilege policies on corporate devices.
  • Patch known vulnerabilities in industrial systems (e.g., Hikvision cameras) and segment PLC networks from general IT traffic.
  • Detect and block custom wiper binaries (Hatef, Hamsa) and backdoor implants using EDR correlation of file hashes.
  • Block or quarantine traffic to Telegram bot C2 infrastructure; restrict outbound access to known Telegram endpoints where feasible.
  • Apply supply‑chain controls: verify Docker image hashes, lock container registries, and monitor GitHub release integrity.
  • Monitor for anomalous Rclone activity to commercial cloud platforms (Wasabi, Backblaze) that may indicate exfiltration.
  • Follow CISA guidance on destructive malware detection and apply hardening guidelines from ST10‑001.
  • Maintain a catalog of known domains associated with the group’s operations and use threat intelligence feeds to block them preemptively.

Suggested Tags

Iran-aligned
Pro-Palestinian
State-sponsored
APT
Disruption-focused
Wiper Malware
DDoS Attack
Backdoor Implant
Industrial Control System Exploit
Ransomware Capable
Hack‑and‑Leak
Political Defacement

Confidence Assessment

The available information derives from publicly documented incidents and open‑source intelligence, providing a high confidence level regarding the actor’s TTPs and campaign patterns. However, gaps remain around internal attribution certainty, precise operational tempo over time, full sophistication assessment, and undisclosed internal toolchains or infrastructure details.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 URL 2

References

  1. blog.talosintelligence.com — Cited by web research for: the Handala Hack Team
  2. unit42.paloaltonetworks.com — Cited by web research for: Cyber Av3ngers
  3. www.seqrite.com — Cited by web research for: Void Manticore
  4. hawk-eye.io — Cited by web research for: T1190
  5. cyberwarrior76.substack.com — Cited by web research for: T1561
  6. www.fortinet.com — Cited by web research for: OilRig
  7. https://www.cisa.gov — Cited by AI analysis.
  8. https://github.com — Cited by AI analysis.

Intel Summary

34

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

DDoS
Government Targeting
Hacktivism
Disruption
Government
Middle East
Eastern Europe
Iran-aligned
Pro-Palestinian
State-sponsored
APT
Disruption-focused
Wiper Malware
DDoS Attack
Backdoor Implant
Industrial Control System Exploit
Ransomware Capable
Hack‑and‑Leak
Political Defacement

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.