Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict
Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict
Read Time:3 Minute, 26 Second

The ongoing conflict between the United States and Iran has turned into a live demonstration of how quickly loosely organized hacktivist networks can mobilize once a kinetic conflict breaks out. A new analysis from DomainTools CISO Daniel Schwalbe maps out the sprawling coalition of pro-Iran hacktivists, nationalist actors, cyber militias, and state-adjacent proxies that have escalated attacks against US and allied targets since February.

The Trigger: February’s Joint Strikes

After the United States and Israel carried out joint military strikes on Iran in February, Iranian state and state-aligned cyber actors moved quickly to retaliate against American and allied companies, infrastructure, and government targets. The clearest example came in March, when a threat actor known as Handala — linked to Iran’s Ministry of Intelligence and Security — breached medical device manufacturer Stryker Corporation.

Handala reportedly used common infostealer malware to compromise administrator-level accounts, then issued remote wipe commands across Stryker’s global device fleet through Microsoft’s InTune management platform. The attack hit laptops, phones, and servers across 79 countries, with Handala claiming more than 200,000 devices wiped in total. The same month, the group also claimed to have hacked and leaked the personal email of FBI Director Kash Patel.

Commercialized DDoS Enters the Picture

In May, an Iraqi resistance-branded group with pro-Iranian ties known as the Islamic Cyber Resistance, or 313 Team, targeted Canonical and Ubuntu’s infrastructure using a DDoS-for-hire platform called “Beamed,” advertised as capable of exceeding 3.5 terabits per second in attack traffic. The campaign knocked several official Ubuntu websites and its security API offline, blocking users from downloading critical updates, and was paired with an extortion demand threatening continued attacks unless Canonical paid up.

The Canonical incident illustrates a broader trend: commercialized DDoS platforms let groups with limited technical depth generate outsized disruption and headlines simply by aiming at widely used enterprise and cloud infrastructure.

A Coalition, Not a Command Structure

Handala and 313 Team may be the most visible names, but Schwalbe’s analysis describes them as just two nodes in a much larger, loosely knit network that includes groups such as RipperSec, Cyb3rDrag0nzz, Cyber Fattah, the Fatimiyoun/FAD Team, Conquerors Electronic Army, Dark Storm, Cyber Isnaad Front, the Cyber Jihad Movement (CJM), APT Iran, Hider Nex, Keymous+, DieNet, and even pro-Russia opportunists like Killnet and MONARCH (Russian Legion).

These groups don’t operate under a unified command. Instead, they coordinate informally over Telegram, sharing target lists, DDoS-for-hire tools, and amplifying one another’s claims of success — creating the appearance of a broad, coordinated cyber front even without centralized planning.

Different Groups, Different Roles

  • Disruption specialists like Handala and 313 Team generate persistent, large-scale impact even with relatively basic tradecraft.
  • Psychological pressure actors such as Fatimiyoun/FAD Team and Cyber Isnaad Front focus on publishing target lists and intimidation campaigns against critical infrastructure operators.
  • Recruitment and amplification nodes like the Cyber Jihad Movement extend the ecosystem’s reach by calling for broader “cyber jihad” participation across platforms.
  • Reconnaissance actors such as Evil Markhors focus on credential harvesting and discovering exposed systems.
  • Volume amplifiers including Keymous+ and DieNet have driven some of the highest-volume DDoS campaigns of the conflict.

Why This Matters for Defenders

Across the ecosystem, the common thread is a reliance on low-sophistication, widely available methods — DDoS-for-hire, website defacement, credential reuse, recycled breach data, and propaganda — rather than novel exploits. What the coalition lacks in technical sophistication, it makes up for in speed and volume: claims of new breaches tend to surface within hours of any kinetic escalation, regardless of whether they hold up to scrutiny.

Schwalbe’s guidance for defenders centers on DDoS readiness, monitoring for leaked credentials, watching for executive doxxing attempts, and having a rapid-response communications plan ready for unverified breach claims. The core caution: a claim posted to Telegram is not proof of a breach, and a leaked data sample does not confirm ongoing access. The coalition’s real value to Iran, the analysis concludes, isn’t as a high-end cyber weapon but as a scalable, low-cost system for generating wartime psychological pressure through mobilization and amplification.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict, use the discussion on Forum.

>> forum community

Comments

Leave a Reply