Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Altahrea Team

Description

Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for a number of cyberattacks, including DDoS attacks against Israeli websites, a hack of the Israel Airports Authority website, and a cyberattack on the Orot Yosef power plant in Israel.

AI Analysis

· 1 week ago

Executive Summary

Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for several cyberattacks targeting Israeli entities, including DDoS attacks against websites and compromising critical infrastructure such as power plants. Their activities suggest a strategic focus on disrupting regional stability through cyber means.

Goals & Targeting

Altahrea Team's strategic objectives likely align with broader Iranian interests in the region, including undermining Israeli infrastructure and demonstrating capabilities to disrupt national stability. Their targeting profile focuses on critical sectors such as energy, transportation, and government, suggesting a focus on maximizing impact through high-profile attacks. The group's victims primarily include state-linked entities and critical infrastructure operators in Israel.

Enhanced Description

Altahrea Team is identified as a pro-Iranian hacking collective, known for conducting cyberattacks that appear to align with broader geopolitical interests of Iran. The group has demonstrated operational persistence since at least 2020, targeting high-profile entities in Israel, including government and critical infrastructure sectors. Their attacks include DDoS campaigns against Israeli websites and breaches of the Israel Airports Authority and Orot Yosef power plant. While specific technical details about their methods are limited, their actions suggest a focus on causing disruption and potentially sending political messages. The group's targeting appears to be geographically focused on Israel, with no confirmed operations outside the Middle East as of yet.

Key Capabilities

  • Conducting DDoS attacks
  • Compromising critical infrastructure systems
  • Potential state-sponsored cyber capabilities

MITRE ATT&CK Tactics

Disruption
Initial Access

ATT&CK Techniques

T1059.003
T1201

Software / Tooling

DDoS tools (e.g., Mirai, Kaiten)
Custom malware (potential)

Campaigns & Victims

Altahrea Team's campaign patterns suggest a focus on high-impact targets within Israel. Their operational tempo appears to be opportunistic but geographically constrained. Notable operations include the Orot Yosef power plant attack and multiple DDoS incidents against Israeli websites. The group has not been linked to large-scale campaigns outside the region, though their persistence indicates potential long-term goals.

IOC Patterns

  • DDoS attack signatures targeting .il domains
  • Network traffic anomalies in critical infrastructure sectors
  • Potential use of Iranian-linked threat infrastructure

Recommended Actions

  • Monitor for DDoS activity originating from known malicious IPs or regions
  • Implement network segmentation to mitigate infrastructure attacks
  • Conduct regular security audits on critical systems
  • Maintain heightened vigilance for APT-related indicators in Israel-focused sectors

Suggested Tags

State-sponsored
Geopolitical
Critical infrastructure
DDoS

Confidence Assessment

Confidence in Altahrea Team's activity is moderate due to the limited公开 details about their TTPs and tools. While their claimed operations are credible, the lack of detailed technical analysis leaves gaps in understanding their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
DDoS
State-sponsored
Geopolitical
Critical infrastructure

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.