Arabian Ghosts is a pro-Iranian, pro-Palestinian hacktivist persona active in the Israel-Iran cyber confrontation and broader anti-Israel campaigns. The group is associated with disruptive operations and propaganda amplification rather than clearly demonstrated advanced intrusion tradecraft, although it has been linked in reporting to attacks and claims involving critical infrastructure and satellite-related targets. Known aliases include Arabian Ghost, ArabianGhosts, and Arabian Ghosts. Arabian Ghosts has been observed participating in coordinated hacktivist ecosystems alongside groups such as GhostSec and other anti-Israel collectives. Its activity has included distributed denial-of-service attacks, website defacements, broad threat messaging, and amplification of allied groups' calls for cyber operations. Reported targeting has included Israeli government and critical infrastructure entities, including financial and healthcare organizations, as well as satellite operators and VSAT-related assets. The group has also been named in reporting on attempts to target programmable logic controllers connected to Israeli media and water systems, placing it within the wider trend of ideologically branded actors claiming or attempting OT/ICS disruption. Public reporting ties Arabian Ghosts to campaigns branded around anti-Israel operations and to threat messaging directed not only at Israel but also at the United States, Saudi Arabia, and the United Arab Emirates. Some assessments describe the actor as likely operating from Syria, but this remains an origin hypothesis rather than a firmly established attribution. As with many regional hacktivist actors, attribution is complicated by coalition behavior, recycled narratives, and exaggerated or unverified claims. The dominant pattern is ideologically motivated disruptive activity focused on denial-of-service, defacement, psychological impact, and claimed interference with critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group issuing broad threat statements under #OpIsraelTeam branding against Israel, the US, Saudi Arabia, and the UAE.
Hacktivist group involved in DDoS/defacement and claimed intrusions targeting Israeli satellite operators/VSAT terminals for disruption and information warfare.
Arabian Ghosts is an Iran-affiliated group involved in targeting PLCs in Israeli media and water systems, contributing to Iranian OT/ICS threat activity.
Regional hacktivist actor now aligned with anti-Israel operations; claims DDoS/defacement and some ICS/OT disruption and data leaks; has floated an unconfirmed ransomware project.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.