Also known as: Fraternal Jackal
**Targets:** The websites of Bank of America, JPMorgan Chase, Wells Fargo, and other U.S. financial institutions suffered simultaneous outages due to a coordinated denial of service cyberattack in September 2012. Attackers flooded bank servers with junk traffic, preventing users from online banking. An Iranian group called Izz ad-Din al-Qassam Cyber Fighters initially claimed responsibility for the incident. At the time, the media reported that U.S. intelligence believed the denial of service was in response to U.S. imposed economic sanctions to counter Irans nuclear program. Seven Iranian individuals linked to the Islamic Revolutionary Guard Corps were eventually indicted by the U.S. Department of Justice in 2016 for their involvement in the incident. **Modus Operandi:** DoS
Ababil / ApAbabil; DoS
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Cyber fighters of Izz Ad-Din Al Qassam, also known as Fraternal Jackal, are nation-state cyber actors primarily motivated by financial gain and political retaliation. Notable for their involvement in the 2012 coordinated DDoS attacks against major U.S. financial institutions, they employ sophisticated DoS tactics to disrupt critical infrastructure and retaliate against economic sanctions imposed on Iran.
Goals & Targeting
The group's strategic objectives appear to be a combination of financial gain through disrupting critical infrastructure and retaliatory actions against perceived adversaries. They target sectors such as financial services for direct financial impact and government/media sectors for broader political influence. Their geographic focus on the U.S. and Iran suggests a desire to disrupt Western economic interests while defending Iranian national interests.
Enhanced Description
The Cyber fighters of Izz Ad-Din Al Qassam (CfiQ) are a state-sponsored cyber threat group linked to Iran. Their primary activity involves large-scale DDoS attacks targeting financial, energy, government, and media sectors. The group gained notoriety in 2012 when they launched simultaneous DDoS campaigns against major U.S. banks like Bank of America and JPMorgan Chase, causing significant disruption. These attacks were initially attributed to retaliatory motives against U.S. economic sanctions targeting Iran's nuclear program but are also believed to have financial motivations. CfiQ is known for their use of specialized DDoS tools like Ababil and ApAbabil, which enable high-volume traffic generation. Their operations continue to evolve, with ongoing campaigns observed beyond 2016.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CfiQ has demonstrated a long-term operational pattern, with notable campaigns including the Ababil and ApAbabil series targeting financial institutions. Their modus operandi involves synchronized volumetric DDoS attacks to overwhelm targeted systems, causing significant disruption. Campaigns often coincide with geopolitical tensions, such as U.S.-Iran relations over nuclear programs or economic sanctions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in available data, particularly regarding their technical capabilities beyond DDoS. Limited visibility into new tools or attack vectors post-2016.
No techniques linked yet.
No tools linked yet.
Ababil / ApAbabil
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics