Also known as: Zeff Security, APT28, Pawn Storm, Fancy Bear, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, APT29, repeated intrusions into government, diplomatic networks across, UNC3944, Caesars Entertainment, causing hundr, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Sednit, TG-0110, Hammertoss, Patchwork, Cozy Bear, Octo Tempest
ZeffSec is a hacktivist collective focused on infrastructure-level disruption and exposing vulnerabilities in centralized digital networks. In March 2026, the group claimed responsibility for a large-scale DDoS attack against ArvanCloud, Iran's primary cloud and CDN provider, causing widespread service outages across platforms including the online education service Skyroom. The group announced the operation via Telegram, stating their goal was disruption of centralized infrastructure rather than data theft.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ZeffSec is a hacktivist collective known for infrastructure-level disruption and DDoS attacks. They recently targeted ArvanCloud, Iran's primary cloud provider, causing significant outages. Their operations are typically announced through channels like Telegram.
Goals & Targeting
ZeffSec's objectives appear to be disrupting centralized digital infrastructure to expose vulnerabilities and highlight potential systemic risks. Their targeting of ArvanCloud suggests a particular interest in critical internet service providers, potentially with an emphasis on those operating in regions like the Middle East. The group likely seeks to impact both technical infrastructure and public perception of cyber resilience.
Enhanced Description
ZeffSec operates primarily as a hacktivist group with a focus on disrupting centralized digital networks. Their modus operandi involves large-scale DDoS attacks aimed at crippling critical infrastructure rather than pursuing data theft or financial gain. The group gained notoriety in March 2026 when they claimed responsibility for a DDoS attack against ArvanCloud, Iran's main cloud and CDN provider. This attack caused widespread service outages across platforms such as Skyroom, an online education service. ZeffSec's activities suggest a strategic focus on targeting vulnerable infrastructure to create disruption and raise awareness about security weaknesses.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ZeffSec's campaign against ArvanCloud indicates a focus on disrupting critical service providers. Their use of Telegram for communication and claims of responsibility suggests an interest in publicizing their actions. The group likely operates with a network of supporters or members willing to participate in distributed attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in ZeffSec's profile is moderate due to limited publicly available information. Additional data on their attack methods, tools, and long-term goals would improve understanding.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
42
Tools
0
Campaigns
18
IOCs
0
Observed Data
0
Tactics