Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors [Unnamed group]

Description

Over the last few weeks, several significant leaks regarding a number of Iranian APTs took place. After analyzing and investigating the documents we conclude that they are authentic. Consequently, this causes considerable harm to the groups and their operation. The identity of the actor behind the leak is currently unknown, however based on the scope and the quality of the exposed documents and information, it appears that they are professional and highly capable. This leak will likely hamstring the groups' operation in the near future. Accordingly, in our assessment this will minimize the risk of potential attacks in the next few months and possibly even year. Note -most of the leaks are posted on Telegram channels that were created specifically for this purpose. Below are the three main Telegram groups on which the leaks were posted: Lab Dookhtegam pseudonym ("The people whose lips are stitched and sealed" –translation from Persian) –In this channel attack tools attributed to the group 'OilRig' were leaked; including a webshell that was inserted into the Technion, various tools that were used for DNS attacks, and more. Green Leakers–In this channel attack tools attributed to the group 'MuddyWatter' were leaked. The group's name and its symbol are identified with the "green movement", which led the protests in Iran after the Presidential elections in 2009. These protests were heavily repressed by the revolutionary guards (IRGC) Black Box–Unlike the previous two channels this has been around for a long time. On Friday May 5th, dozens of confidential documents labeled as "secret" (a high confidentiality level in Iran, one before the highest -top secret) were posted on this channel. The documents were related to Iranian attack groups' activity.

AI Analysis

· 2 weeks ago

Executive Summary

The Unnamed group, a sophisticated actor believed to be targeting Iranian Advanced Persistent Threat (APT) groups, has emerged as a significant threat due to their ability to leak sensitive information and disrupt operations. Their activities, particularly the exposure of attack tools and confidential documents through Telegram channels, have caused considerable harm to targeted groups, potentially reducing threat activity in the near term.

Goals & Targeting

The Unnamed group likely targets Iranian APTs to disrupt their operations and reduce their effectiveness as a threat actor. Their focus on exposing sensitive information suggests an intent to discredit these groups and limit their ability to carry out attacks. The leaks posted on Telegram channels indicate a strategic approach to targeting sectors involved in cyber espionage and potentially politically sensitive activities.

Enhanced Description

The Unnamed group is a professional and highly capable cyber threat actor whose primary focus appears to be disrupting Iranian APT operations. Their activities include the leakage of sensitive information, attack tools, and confidential documents through various Telegram channels. These leaks have exposed operational details, tools, and strategies used by groups such as OilRig and MuddyWatter, significantly hampering their ability to conduct further attacks. The group's motivation seems to be aligned with undermining Iranian state-sponsored cyber activities, potentially aligning with broader geopolitical goals.

Key Capabilities

  • Highly sophisticated operational security
  • Proficient in leaking confidential documents
  • Expertise in exposing APT tools and techniques
  • Use of anonymous communication platforms (Telegram)
  • Strategic targeting of sensitive information

MITRE ATT&CK Tactics

Espionage
Disruption

ATT&CK Techniques

T1056.002
T1078
T1003
T1564
T1259

Software / Tooling

Telegram channels
Anonymous communication tools
Information exfiltration frameworks

Campaigns & Victims

The Unnamed group has demonstrated a persistent and methodical approach to leaking information. Their campaign patterns include the strategic timing of leaks, particularly around significant events such as political protests in Iran. Notable operations include the exposure of high-confidentiality documents on 'Black Box' Telegram channel and the leak of OilRig and MuddyWatter tools on other channels.

IOC Patterns

  • Use of Telegram channels for information dissemination
  • Sudden appearance of confidential documents online
  • Exposure of APT toolkits through publicly accessible platforms

Recommended Actions

  • Monitor Telegram channels for potential leaks related to your organization.
  • Enhance internal security protocols to prevent unauthorized data exposure.
  • Conduct regular audits of sensitive systems and communications tools.
  • Implement employee training to recognize phishing attempts or suspicious activity.

Suggested Tags

APT
Iranian Cyber Threat
Cyber Espionage
Disruption Campaign

Confidence Assessment

High confidence in the assessment of the Unnamed group's sophistication and capabilities, based on the quality and scope of leaked information. However, gaps remain in identifying the group's exact affiliation or broader objectives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Government Targeting
Hacktivism
APT
Iranian Cyber Threat
Cyber Espionage
Disruption Campaign

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.