Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cyber Islamic Resistance

Cyber Islamic Resistance

APT35 TLP:CLEAR
Active

Also known as: tracked as, 313 Team, Team 313, Charming Kitten, Mint Sandstorm, journalists, researchers, policy communities, Holy Souls, Emennet Pasargad, meanwhile, Western institutions, APT34, Cyber Av3ngers, Storm-0784, DarkStorm, ransomware, Void Manticore, Earth Preta, TA416, DeadCatx3, PCPcat, 2026, Altoufan Team, GalaxyGato, Nimbus Manticore, aerospace, telecommunications, regional government enti, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, APT35, Group 83, MRHELL112, INC Ransomware, Storm-0842, Bronze President, ShellForce, Tunisian Maskers Cyber Force, Haywire Kitten, Subtle Snail, Newscaster Team, Magic Hound, G0059, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION

Description

Cyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website defacements, DDoS attacks, and data exfiltration targeting Israeli and Western entities. They have claimed breaches of Israeli cybersecurity firms and academic platforms, framing their actions as part of a broader narrative of retaliation. The group has also targeted critical infrastructure, asserting access to industrial control systems and operational technology environments. Their activities are often presented as part of a coordinated cyber mobilization campaign, emphasizing psychological and reputational impacts.

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Energy
Critical infrastructure
Healthcare
Non profit
Media
Manufacturing
Aerospace
Maritime
Transportation
Utilities
Aviation
Pharmaceutical
Information technology
Education
Oil gas
Mining
Nuclear
Think tank

Targeted Countries / Regions

IR
IL
AE
US
LB
IQ
TR
SA
NL
RU
EG
AZ
UA
SY
PK
KR
IN
CN

AI Analysis

· 1 week ago

Executive Summary

Cyber Islamic Resistance is a hacktivist collective aligned with Iranian interests, conducting disruptive cyber operations targeting Israeli and Western entities. Their activities include DDoS attacks, website defacements, and data exfiltration, often framed as retaliatory actions against perceived adversaries. The group's primary goals appear to be ideological, aiming to weaken the perception of Israel and its allies while promoting a narrative of resistance against Western influence.

Goals & Targeting

The group's strategic objectives appear to be primarily ideological, with a focus on weakening the image and capabilities of Israel and its Western allies through disruptive cyber operations. They target sectors such as cybersecurity firms, academic institutions, and critical infrastructure, possibly due to their symbolic importance and perceived vulnerability. Their targeting of Israeli entities aligns with broader geopolitical narratives and conflicts in the Middle East.

Enhanced Description

Cyber Islamic Resistance operates as a hacktivist collective with suspected ties to Iran, engaging in both disruptive and potentially damaging cyber activities. Their operations include DDoS attacks, website defacements, and data exfiltration, often targeting Israeli entities, cybersecurity firms, and academic platforms. These actions are presented by the group as part of a broader narrative of 'resistance' against Western and Israeli interests. The collective's claims of breaching industrial control systems suggest some level of sophistication in targeting critical infrastructure. Their activities focus on creating psychological and reputational damage, leveraging cyber means to amplify their ideological message.

Key Capabilities

  • DDoS attacks
  • Website defacements
  • Data exfiltration
  • Access to industrial control systems
  • Advanced persistent threat (APT) campaign capabilities

MITRE ATT&CK Tactics

Network Operations
Collection
Exfiltration
Defense Evasion

ATT&CK Techniques

T1566.002
T1486.001
T1071.001
T1055
T1223

Software / Tooling

Custom malware
Indicators of Compromise (IOCs) related to DDoS campaigns
Lateral movement tools

Campaigns & Victims

Cyber Islamic Resistance appears to operate with a structured campaign approach, focusing on high-profile targets in sectors that align with their ideological goals. Their operations often include pre-attack research and planning, coordinated efforts, and post-incident propaganda. Notable campaigns have included claims of breaching cybersecurity firms and academic platforms, suggesting an interest in both technical vulnerabilities and reputational damage.

IOC Patterns

  • DDoS attack patterns against specific industries or regions
  • Presence of malicious scripts on compromised websites
  • Unusual network traffic from industrial control systems
  • Phishing campaigns targeting key sectors

Recommended Actions

  • Implement robust DDoS protection and monitoring solutions.
  • Enhance network perimeter security to prevent unauthorized access.
  • Monitor for unusual activity in industrial control systems environments.
  • Conduct regular employee training on identifying phishing attempts.
  • Develop incident response plans tailored to potential hacktivist attacks.

Suggested Tags

APT
Hacktivism
Geopolitical
Middle East/North Africa (MENA) focus

Confidence Assessment

Moderate confidence in the group's existence and general activities due to their claims of attacks and media reports. However, there is uncertainty regarding specific tools, techniques, and确切的 campaign details beyond what has been publicly claimed or attributed.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Email Address 1 Filename 1

References

  1. www.rapid7.com — Cited by web research for: Charming Kitten
  2. unit42.paloaltonetworks.com — Cited by web research for: Cyber Av3ngers
  3. www.seqrite.com — Cited by web research for: Void Manticore
  4. thehackernews.com — Cited by web research for: 2026
  5. cyberwarrior76.substack.com — Cited by web research for: T1485
  6. cstromblad.com — Cited by web research for: T1574.002

Intel Summary

40

Techniques

51

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Critical Infrastructure
Data Exfiltration
DDoS
Hacktivism
APT
Geopolitical
Middle East/North Africa (MENA) focus

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Disruption
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.