Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors malekteam

Description

Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel), believed to be tied to Iranian military intelligence, primarily targeting Israeli organizations using data exfiltration and extortion, with notable attacks on Ziv Medical Center and Ono Academic College. Known victims: 7

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Malek Team is a medium-sophistication Iranian-linked threat actor primarily targeting Israeli organizations with ransomware and extortion activities. Emerging after the Hamas attack on Israel, they have targeted sectors including healthcare and education.

Goals & Targeting

The primary objectives of Malek Team appear to be financial gain through ransomware campaigns and organizational disruption. Their targeting focus is concentrated on Israel, likely due to both geopolitical motivations and the availability of high-value targets in critical sectors such as healthcare and education.

Enhanced Description

Malek Team is an Iran-based cybercriminal group that has gained notoriety for its attacks on Israeli institutions. The group's operations are believed to be linked to Iranian military intelligence, suggesting a possible state-sponsored component to their activities. Their primary tactics include data exfiltration and extortion, with notable victims including Ziv Medical Center and Ono Academic College. The group's rise coincided with significant regional geopolitical events, indicating potential operational motivation tied to broader strategic goals.

Key Capabilities

  • Data exfiltration
  • Ransomware deployment
  • Extortion tactics

Campaigns & Victims

Malek Team has demonstrated a focus on high-profile targets within Israel, suggesting an operational strategy aimed at maximizing media impact and financial gain. Their campaigns have included attacks on sensitive infrastructure such as medical facilities, potentially indicating a desire to cause significant disruption. While their activity window is limited to late 2023 and early 2024, the group has shown persistence in targeting specific sectors.

IOC Patterns

  • Targeted phishing attempts
  • Ransomware deployment
  • Data exfiltration activities

Recommended Actions

  • Implement robust email security measures to detect and block phishing campaigns.
  • Enhance network monitoring for signs of data exfiltration.
  • Conduct regular backup procedures to mitigate ransomware attacks.

Suggested Tags

APT
ransomware
extortion
Israel-focused

Confidence Assessment

Low confidence due to limited available intelligence on Malek Team's specific tactics, techniques, and procedures (TTPs). There is a lack of detailed information on their tools, campaigns, and Indicators of Compromise (IoCs), making comprehensive analysis challenging.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
Data Exfiltration
Government Targeting
APT
ransomware
extortion
Israel-focused

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 24, 2023
Last Seen
Apr 5, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.