Cyber Fattah, also known as Cyber Fattah Team and cyber_fattah_team, is an Iran-aligned hacktivist collective conducting disruptive cyber operations and information warfare in support of pro-Iranian and pro-Palestinian causes. The group identifies itself as an Iranian cyber team and is associated with the IRGC-aligned hacktivist ecosystem. Its operations emphasize political messaging, disruption, and public exposure of sensitive information rather than conventional financially motivated cybercrime. Its targets include Israeli infrastructure, government agencies, educational institutions, and media organizations, as well as Saudi sporting-event infrastructure. Its activities include reconnaissance, distributed denial-of-service attacks, website defacement, and data theft. In June 2025, it publicized a Saudi Games breach involving unauthorized access to phpMyAdmin and exfiltration of database records containing sensitive personal information and documents belonging to athletes and visitors. Cyber Fattah uses Telegram for mobilization, target announcements, attack claims, leaked-data distribution, and propaganda amplification. It collaborates with 313 Team and other resistance-branded groups within the broader pro-Iranian cyber coalition. Its activity has intensified during Iran–Israel military escalations, combining technical disruption with psychological pressure and coordinated narrative amplification.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
1 more CVE tied to this actor tracked in Mallory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an aligned resistance-branded group within the broader pro-Iran cyber coalition.
Hacktivist actor contributing attack volume and propaganda amplification within the pro-Iran ecosystem.
Hacktivist group described as activated by Iran following the U.S.-Israel attacks.
Iranian-aligned hacktivist group participating in coordinated cyber activity during the 2026 Iran conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.