Cyber Fattah is a pro-Iranian hacktivist group active in the broader Iran-aligned cyber proxy and influence ecosystem. The group presents itself as an Iranian cyber team and has been described as Iranian-backed or affiliated, while some reporting also places it among Palestinian-linked cells operating within the same resistance-branded coalition. Cyber Fattah is associated with the wider Cyber Islamic Resistance and allied networks that include actors such as 313 Team, Fatimiyoun/FAD Team, DieNet, Keymous+, RipperSec, Cyb3rDrag0nzz, and Conquerors Electronic Army. Its branding aligns with Tehran’s military-industrial narrative, and its activity has repeatedly tracked regional military escalation involving Iran, Israel, the United States, and Gulf states. The group’s operations are primarily hacktivist and coercive rather than highly sophisticated state-APT tradecraft. Reported activity includes reconnaissance, distributed denial-of-service attacks, website defacements, data theft, leak and data-dump operations, propaganda amplification, and information warfare. Cyber Fattah has used Telegram extensively to rally participants, announce targets, amplify coalition claims, and broadcast narratives, consistent with the mobilization patterns of the broader pro-Iran cyber ecosystem. Cyber Fattah has targeted Israeli infrastructure and institutions, including media and education-related entities, and has also been linked to attacks or claimed intrusions affecting Saudi and other Gulf interests. Reported incidents include publication of personal records tied to the Saudi Games, targeting of Israeli organizations during wartime cyber campaigns, and participation in broader anti-Israel and anti-Western operations coordinated with allied hacktivist groups. The group has also been associated with scanning Israeli network ranges for exposed internet-connected devices during periods of conflict escalation. Cyber Fattah has additionally been linked to ransomware-adjacent activity through collaboration in channels associated with Liwaa Mohammad and the Cyber Islamic Resistance ecosystem. It claimed use of the React2Shell vulnerability for initial access and reported successful deployment of BQTLock against an Israeli victim. This places the group at the intersection of hacktivism, disruptive operations, data theft, and ideologically framed extortion tooling, although its overall profile remains closer to a proxy hacktivist actor than a mature ransomware operator. Available reporting consistently places Cyber Fattah within Iran’s layered proxy cyber strategy, in which loosely coordinated hacktivist brands, ideological cyber militias, and state-adjacent actors provide deniability, rapid mobilization, and psychological pressure during geopolitical crises.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
1 more CVE tied to this actor tracked in Mallory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an aligned resistance-branded group within the broader pro-Iran cyber coalition.
Hacktivist actor contributing attack volume and propaganda amplification within the pro-Iran ecosystem.
Hacktivist group described as activated by Iran following the U.S.-Israel attacks.
Iranian-aligned hacktivist group participating in coordinated cyber activity during the 2026 Iran conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.