Druidfly, also known as Homeland Justice and Karma, is an Iranian threat actor associated with destructive cyber operations, particularly disk-wiping attacks. The group has been linked to campaigns targeting organizations in Albania and is notable for using wiper malware in politically motivated disruptive operations. Reported pre-destructive tradecraft has included staging access and tooling such as remote administration software, web shells, and malware used to prepare victim environments before activation of wiping payloads, including BibiWiper and HTTPSnoop. Druidfly is best characterized as an Iranian-aligned destructive actor focused on disruptive impact rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor maintaining pre-staged destructive capability using BibiWiper supported by malware, RMM tools, and web shells.
Iranian attack group specializing in destructive disk-wiping operations, notably against Albania and Israel, often operating under hacktivist personas while conducting state-linked disruptive and destructive attacks.
Destructive attacks and espionage operations targeting countries hostile to Iran, including Albania and Israel, using wipers, ransomware, and social engineering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.