Cyb3r Drag0nz, also referred to as Cyb3r Drag0nz Team, is a pro-Iran hacktivist persona active in the Iran-Israel cyber conflict ecosystem. The group has been associated with politically motivated disruptive and propaganda-oriented operations rather than high-end intrusion tradecraft. It has been observed participating in campaigns framed as retaliation against Israeli interests and has publicly aligned itself with the Electronic Operations Room of Islamic Resistance Axis, a broader umbrella for Iran-aligned online personas seeking to disrupt Israeli organizations and infrastructure. The group is known for low-sophistication operations and inflated or embellished public claims, consistent with a wider pattern among regional hacktivist brands that emphasize psychological impact, narrative amplification, and symbolic targeting. Reported activity linked to Cyb3r Drag0nz includes distributed denial-of-service attacks, website defacements, and data leak activity. The actor has also been tied to doxxing and leak-oriented messaging in the broader pro-Palestinian and pro-Iran online ecosystem. Available reporting characterizes its operations as disruptive and influence-oriented, with limited evidence of sophisticated state-grade capabilities. Cyb3r Drag0nz has appeared alongside other Iran-aligned personas including Handala Hack Team, APTIran, Cyber Toufan, Cyber Support Front, Iranian Avenger, and DieNet. Its integration into the Electronic Operations Room indicates coordination or at minimum public alignment with a coalition of anti-Israel hacktivist actors. The dominant pattern associated with Cyb3r Drag0nz is hacktivism in support of Iranian and anti-Israeli political objectives, using DDoS, defacement, and leak claims to impose reputational costs and signal solidarity rather than to deliver consistently verified strategic cyber effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned persona observed operating through the Electronic Operations Room of Islamic Resistance Axis.
Hacktivist group integrated into the Electronic Operations Room during the 2026 escalation.
Hacktivist group claiming participation in a broader anti-Israel cyber effort aimed at disrupting Israeli organizations and infrastructure.
Emerging or reactivated pro-Iran group engaged mainly in unsophisticated tactics, embellished claims, and retaliatory messaging amplification.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.