DieNet is a pro-Iranian hacktivist collective that emerged publicly on Telegram in March 2025. It primarily conducts politically motivated, high-volume distributed denial-of-service (DDoS) campaigns against the United States, Israel, and their regional partners. Its targets include government institutions, military websites, banks, telecommunications providers, airports, transit systems, utilities, technology companies, healthcare organizations, and Trump-affiliated businesses. The group has used versioned branding, including DieNet-v2 and DieNet-v5, following channel bans and subsequent relaunches. DieNet operates both as a disruption collective and as a supplier of DDoS infrastructure and toolkits to allied hacktivists. Its operational model relies on rented DDoS-as-a-service infrastructure rather than bespoke malware development. Its attack repertoire includes TCP SYN and RST floods, DNS and NTP amplification, and application-layer attacks. It distributes structured target lists and uses automated third-party availability checks to assess and publicize disruption. Telegram serves as a platform for coordination, recruitment, attack announcements, and amplification of allied groups' claims. During the February–March 2026 Middle East escalation, DieNet became a major volume driver within the pro-Iranian hacktivist ecosystem, coordinating synchronized attacks across Gulf states through the Cyber Islamic Resistance Electronic Operations Room. DieNet and Keymous+ together accounted for nearly 70 percent of recorded hacktivist activity between February 28 and March 2, 2026. DieNet has also collaborated with Sylhet Gang-SG and Team Azrael against Indian government portals. Its established operational focus is network and application availability disruption, combined with symbolic targeting and propaganda amplification.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Contributes DDoS activity and propaganda amplification; specifically noted for some of the highest-volume DDoS campaigns of the conflict.
Hacktivist actor in the pro-Iran/Axis-aligned ecosystem contributing high attack volume, rhetoric, target lists, and claims amplification during crisis-driven campaigns.
Iran-aligned persona operating through the Electronic Operations Room of Islamic Resistance Axis; specifically claimed DDoS attacks against airports and banks.
Hacktivist support network and toolkit provider supplying DDoS capability, target lists, and automated verification for Gulf-focused operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.