Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cyber fighters of Izz Ad-Din Al Qassam

Cyber fighters of Izz Ad-Din Al Qassam

TLP:CLEAR
Active

Also known as: Fraternal Jackal

Description

**Targets:** The websites of Bank of America, JPMorgan Chase, Wells Fargo, and other U.S. financial institutions suffered simultaneous outages due to a coordinated denial of service cyberattack in September 2012. Attackers flooded bank servers with junk traffic, preventing users from online banking. An Iranian group called Izz ad-Din al-Qassam Cyber Fighters initially claimed responsibility for the incident. At the time, the media reported that U.S. intelligence believed the denial of service was in response to U.S. imposed economic sanctions to counter Irans nuclear program. Seven Iranian individuals linked to the Islamic Revolutionary Guard Corps were eventually indicted by the U.S. Department of Justice in 2016 for their involvement in the incident. **Modus Operandi:** DoS

TTP Summary

Ababil / ApAbabil; DoS

Goals & Targeting

Targeted Sectors

Financial services
Media
Energy
Government

Targeted Countries / Regions

US
IR

AI Analysis

· 1 week ago

Executive Summary

The Cyber fighters of Izz Ad-Din Al Qassam, also known as Fraternal Jackal, are nation-state cyber actors primarily motivated by financial gain and political retaliation. Notable for their involvement in the 2012 coordinated DDoS attacks against major U.S. financial institutions, they employ sophisticated DoS tactics to disrupt critical infrastructure and retaliate against economic sanctions imposed on Iran.

Goals & Targeting

The group's strategic objectives appear to be a combination of financial gain through disrupting critical infrastructure and retaliatory actions against perceived adversaries. They target sectors such as financial services for direct financial impact and government/media sectors for broader political influence. Their geographic focus on the U.S. and Iran suggests a desire to disrupt Western economic interests while defending Iranian national interests.

Enhanced Description

The Cyber fighters of Izz Ad-Din Al Qassam (CfiQ) are a state-sponsored cyber threat group linked to Iran. Their primary activity involves large-scale DDoS attacks targeting financial, energy, government, and media sectors. The group gained notoriety in 2012 when they launched simultaneous DDoS campaigns against major U.S. banks like Bank of America and JPMorgan Chase, causing significant disruption. These attacks were initially attributed to retaliatory motives against U.S. economic sanctions targeting Iran's nuclear program but are also believed to have financial motivations. CfiQ is known for their use of specialized DDoS tools like Ababil and ApAbabil, which enable high-volume traffic generation. Their operations continue to evolve, with ongoing campaigns observed beyond 2016.

Key Capabilities

  • Advanced DDoS capabilities
  • Persistent targeting of critical infrastructure
  • Use of specialized DDoS tools (e.g., Ababil, ApAbabil)

MITRE ATT&CK Tactics

Disruption

ATT&CK Techniques

T1486.002

Software / Tooling

Ababil
ApAbabil

Campaigns & Victims

CfiQ has demonstrated a long-term operational pattern, with notable campaigns including the Ababil and ApAbabil series targeting financial institutions. Their modus operandi involves synchronized volumetric DDoS attacks to overwhelm targeted systems, causing significant disruption. Campaigns often coincide with geopolitical tensions, such as U.S.-Iran relations over nuclear programs or economic sanctions.

IOC Patterns

  • Volumetric DDoS traffic spikes
  • Use of Ababil/APAbabil tools

Recommended Actions

  • Implement advanced DDoS protection solutions
  • Monitor for异常流量patterns associated with high-volume attacks
  • Enhance network perimeter defenses and traffic analysis capabilities.

Suggested Tags

APT
nation-state
financial-gain
DDoS
critical-infrastructure

Confidence Assessment

Moderate confidence in available data, particularly regarding their technical capabilities beyond DDoS. Limited visibility into new tools or attack vectors post-2016.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Financial Targeting
Critical Infrastructure
DDoS
nation-state
financial-gain
critical-infrastructure

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.