cognitive cybersecurity intelligence

News and Analysis

Search

How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict

How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict

The current conflict between the United States and Iran has become a case study in how asymmetric warfare and coalition building are reshaping the cyber and geopolitical dimensions of modern conflict.

Following the United States and Israel’s joint military strikes on Iran in February 2026, Iranian state and state-aligned actors rapidly increased cyber attacks against U.S. and allied companies, infrastructure, and governments. The most notable example is the attack on a U.S. medical device company, Stryker Corporation, in March.

Handala, a threat actor linked to Iran’s Ministry of Intelligence and Security (MOIS), gained access to Stryker using a common infostealer malware and targeted administrator-level accounts to issue remote wipe commands across Stryker’s global network via Microsoft’s InTune management function.

The breach impacted laptops, smartphones, and servers in 79 countries; Handala claimed to have wiped more than 200,000 devices in total. In the same month, Handala also claimed responsibility for hacking and leaking FBI Director Kash Patel’s personal email.

In May 2026, the Islamic Cyber Resistance (aka 313 Team), an Iraqi resistance-branded actor with pro-Iranian affiliations, launched a campaign against Canonical and Ubuntu infrastructure. The group claimed to use a DDoS-for-hire service known as “Beamed” that offers attack capabilities exceeding 3.5 terabits per second.

The attack impacted several official websites and Ubuntu’s security API, rendering them inaccessible and preventing users from accessing critical updates and installations. The group paired the disruption with an extortion demand, threatening to continue the attacks unless Canonical paid a ransom.

The use of commercialized DDoS platforms such as Beamed allows groups with otherwise limited technical sophistication to launch disruptive cyber attacks. By targeting services used in enterprise and cloud environments, the campaign created outsized visibility and operational friction.

While Handala and 313 Team have become two of the more widely discussed actors during this conflict, they are just two players in a much larger coalition of pro-Iran hacktivists, nationalist actors, cyber militias, and state-adjacent proxy influence networks.

These groups operate as a loosely knit cyber mobilization network that projects the image of a broad, transnational cyber front. The Canonical campaign is widely attributed to 313 Team, but this actor is often aligned with other resistance-branded groups – such as RipperSec, Cyb3rDrag0nzz, Cyber Fattah, Fatimiyoun/FAD Team, and Conquerors Electronic Army – as part of a broader coalition that includes Dark Storm, Cyber Isnaad Front, CJM, APT Iran, Hider Nex, Keymous+, DieNet, MONARCH, and Killnet.

These groups amplify one another’s disruption claims and engage in symbolic targeting through shared target lists. Rather than operating under a common command structure, they coordinate on Telegram – sharing target lists and DDoS-for-hire tools, and amplifying each other’s campaigns. Together, they turn relatively low-cost disruption into wartime psychological pressure.

Defending against this type of coalition requires understanding the roles different actors play. Actors like Handala and 313 Team are capable of generating persistent and large-scale disruption despite using, in some cases, relatively unsophisticated methods.

Other actors, such as Fatimiyoun/FAD Team and Cyber Isnaad Front, primarily contribute by creating psychological pressure through published target lists, intimidation campaigns, and threats against critical infrastructure.

Meanwhile, Cyber Jihad Movement (CJM) operates in a different strategic capacity. The group mainly extends the ecosystem’s reach – drawing recruits and amplifying propaganda across platforms – through public statements calling for “global cyber jihad” against the United States, Israel, and allied governments. Evil Markhors fills another niche, focusing on credential harvesting, reconnaissance, and exposed-system discovery.

Figure 1: Pro-Iran / Axis of Resistance Cyber Ecosystem

Remaining actors in this ecosystem fall into two broad categories: DDoS and amplification actors, and opportunistic anti-Western groups. Groups like Nation of Saviors, Dark Storm Team, Cyb3rDrag0nzz, Keymous+, Conquerors Electronic Army, and DieNet primarily contribute DDoS activity and propaganda amplification, with Keymous+ and DieNet responsible for some of the highest-volume DDoS campaigns of the 2026 conflict. The other category includes pro-Russia actors like Killnet, Russian Legion (aka MONARCH), and NoName057(16) that function as opportunistic anti-Western actors, providing symbolic support, amplification, and target selection.

While actors perform different roles and functions within the broader coalition, there are consistent behaviors across the entire ecosystem.

These actors generally rely on low-sophistication or commercially available methods of disruption, including DDoS-for-hire services, website defacements, credential reuse, recycled breach data, public claims, and propaganda amplification.

Behaviorally, they amplify disruption claims and engage in symbolic targeting to create psychological pressure on their adversaries. While this coalition relies on relatively basic tradecraft, defending against their techniques requires more than intrusion prevention. It also requires managing disruption, reputational risk, and alert fatigue across public-facing systems.

During the ongoing conflict between Iran and the U.S., this coalition is likely to mobilize quickly, with claims appearing within hours of kinetic events. Defenders should focus on DDoS readiness, leaked credential monitoring, executive doxxing monitoring, and rapid response and communications procedures for false or exaggerated breach claims. It is crucial to remember that a claim on Telegram is not a proven breach, and a leaked sample does not prove current access.

The bottom line: this coalition is not a high-end cyber weapon but a scalable, asymmetric pressure system whose value comes from mobilization, amplification, and psychological effects.

Author: Daniel Schwalbe, Linkedin.

Daniel Schwalbe is the CISO & Head of Investigations for DomainTools, where he focuses on Security Operations, Governance Risk and Compliance, Endpoint, Internal Incident Response, Physical Security, and Employee Security Awareness. With more than 25 years of experience in IT and Security, Daniel’s background spans startups, higher education, government, and large enterprises.

Additionally, Daniel has a passion for the InfoSec Community and continues to be a regular contributor to organizations like Microsoft DCC, Underground Economy, M3AAWG, NCFTA, SLEUTHCON, and more.
The post How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts