Predatory Sparrow, also known by the Persian name Gonjeshke Darande and sometimes referred to as Indra, is a highly capable anti-Iran cyber threat actor widely reported as linked to Israel, though official state control has not been publicly confirmed. The group emerged publicly by 2021 and has become known for disruptive and destructive operations against Iranian critical infrastructure, financial institutions, industrial environments, transportation-related systems, and cryptocurrency services. It presents itself as acting on behalf of Iranian citizens against the Islamic Republic, but many public assessments characterize it as a state-linked or state-sponsored sabotage actor rather than a conventional hacktivist collective. The actor is associated with repeated attacks on Iran’s fuel distribution ecosystem, including the October 2021 disruption that affected thousands of fuel stations and a later 2023 operation against fuel systems. Reporting on the 2021 incident indicates the operation disrupted subsidized fuel-card services, caused prolonged outages, and soft-bricked point-of-sale devices while central management systems were reportedly wiped. Predatory Sparrow has also been linked to attacks on Iranian rail-related systems, state media, and the steel sector, including a 2022 operation that reportedly caused a fire at an Iranian steel facility. These operations are notable for combining cyber intrusion with operational disruption and, in some cases, destructive effects intended to undermine public confidence and impose real-world costs. In June 2025, Predatory Sparrow claimed responsibility for major attacks on Iranian financial infrastructure. One operation disrupted Bank Sepah, a strategically sensitive Iranian bank with longstanding ties to the state and military sector, causing outages that affected banking services and reportedly had downstream effects on fuel-payment infrastructure. Another operation targeted Nobitex, Iran’s largest cryptocurrency exchange, where the group claimed to have stolen and effectively destroyed roughly $90 million in digital assets while also leaking internal materials. Public reporting consistently frames these actions as politically motivated sabotage aimed at Iranian state capacity, sanctions-evasion mechanisms, and entities allegedly tied to the IRGC and broader regime financing. Observed and reported tradecraft includes initial compromise of centralized management infrastructure, destructive actions against servers and endpoints, soft-bricking of embedded devices, data destruction, service disruption, public claims of responsibility, and information release to amplify coercive or psychological impact. Across its known operations, the group demonstrates capabilities aligned with initial access, post-exploitation, persistence within victim environments, exfiltration or publication of stolen data and internal materials, and destructive or disruptive effects against operational technology and adjacent enterprise systems. Its activity is best characterized as targeted cyber sabotage in support of geopolitical objectives rather than financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Mentioned only as a comparison case for destructive anti-Iran operations; not attributed to the incidents discussed here.
Israel-linked targeted cyber sabotage against Iranian industrial and financial infrastructure intended to damage state capacity, undermine confidence, and disrupt support networks.
Linked to disruptive cyberattacks in Iran affecting fuel distribution and banking systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.