Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ababil of Minab

Also known as: tracked as, Babil of Minab, which has been, ION-87 by Insikt Group, APT42, Charming Kitten, including for debugging, code generation, MuddyWater, including telltale emojis, TA402, APT36, diplomatic missions, government agencies, other strategic entities, backdoor, 560048, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, APT35, Group 83, Mint Sandstorm, Mango Sandstorm, TAG-135, OilRig

Description

Ababil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in threat intelligence reporting. The group claims responsibility for a cyberattack and allegedly possesses administrative access to targeted systems. Their pro-Iran messaging and targeting of a major US public transit authority align with known patterns of Iranian-aligned actors targeting US critical infrastructure. The use of escalatory language suggests potential for further activity.

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Media
Transportation
Defense
Financial services
Manufacturing
Hospitality
Healthcare
Critical infrastructure
Education
Construction
Energy
Non profit
Aviation
Information technology
Maritime
Aerospace
Utilities
Retail
Gaming
Food agriculture

Targeted Countries / Regions

US
IR
IL
RU
MX
SA
CN
UA
JP
CA
TR
AE
PK
IN
SG
IT
FR
GB
ES
NG
IQ
DE
AZ
KZ
RO
NL
AU
EG
BR

AI Analysis

· 2 months ago

Executive Summary

Ababil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile, claiming responsibility for a cyberattack on a major US public transit authority. Their pro-Iran messaging and targeting of US critical infrastructure align with known patterns of Iranian-aligned actors. The group's escalatory language suggests potential for further activity.

Goals & Targeting

Ababil of Minab's strategic objectives appear to be focused on targeting organizations and individuals that are perceived as being opposed to Iranian interests. The group's attacks on US critical infrastructure, such as public transit authorities, suggest that it is seeking to disrupt or intimidate its targets, rather than simply seeking financial gain or notoriety. The group's typical victims are likely to be organizations or individuals that are seen as being aligned with US or Western interests, or that are perceived as being opposed to Iranian interests.

Enhanced Description

Despite the limited information available about Ababil of Minab, it is clear that the group poses a significant threat to organizations that are perceived as being opposed to Iranian interests. The group's claims of administrative access to targeted systems suggest that it may have the capability to carry out sophisticated and potentially damaging attacks. As such, it is essential that organizations take proactive steps to protect themselves from potential attacks by this group, including implementing robust cybersecurity measures and remaining vigilant for signs of suspicious activity.

Key Capabilities

  • Administrative access to targeted systems
  • Cyberattack capabilities
  • Use of escalatory language to intimidate targets

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom malware
Open-source hacking tools

Campaigns & Victims

Ababil of Minab's campaign patterns are not well understood due to the limited information available about the group. However, it is likely that the group will continue to target organizations and individuals that are perceived as being opposed to Iranian interests, using a combination of cyberattacks and intimidatory tactics to achieve its objectives. The group's operational tempo is likely to be characterized by periods of heightened activity, followed by periods of relative quiet, as it seeks to avoid detection and maintain its capabilities.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust cybersecurity measures, including firewalls and intrusion detection systems
  • Conduct regular security audits and vulnerability assessments
  • Remain vigilant for signs of suspicious activity, including unusual network traffic or system behavior

Suggested Tags

APT
hacktivism
Iran-aligned

Confidence Assessment

The confidence level in the available data on Ababil of Minab is low due to the limited information available about the group. There are significant information gaps regarding the group's capabilities, motivations, and intentions, which make it difficult to provide a comprehensive assessment of the threat it poses. Further analysis and reporting are necessary to fully understand the scope of the threat posed by Ababil of Minab.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1 Domain 13 Filename 3 SHA-256 Hash 3

References

  1. www.recordedfuture.com — Cited by web research for: ION-87 by Insikt Group
  2. www.recordedfuture.com — Cited by web research for: APT42
  3. www.cyfirma.com — Cited by web research for: APT36
  4. research.checkpoint.com — Cited by web research for: Spear-phishing
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. thehackernews.com — Cited by web research for: CVE-2026-50522

Intel Summary

40

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

Critical Infrastructure
Hacktivism
APT
hacktivism
Iran-aligned

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.