Cyber Islamic Resistance is a pro-Iranian hacktivist umbrella collective within the Axis of Resistance cyber ecosystem. Also styled The Cyber Islamic Resistance, it coordinates multiple teams conducting politically motivated disruption, website defacement, reconnaissance, and data-theft operations. Its activity is aligned with Iranian regional interests, but this alignment does not establish direct control by a particular Iranian intelligence or military organization. On March 1, 2026, the collective announced a joint Electronic Operations Room and a general cyber mobilization campaign. The coordination structure brought together more than 15 groups, with participants and affiliates including 313 Team, RipperSec, Moroccan Black Cyber Army, and DieNet. Coalition membership is fluid rather than a fixed hierarchy. The collective primarily targets Israel and coordinates campaigns against Gulf states and U.S.-linked entities. Its operations include DDoS attacks, defacements, phishing, and public dissemination of stolen material, combining service disruption with propaganda amplification. Cyber Islamic Resistance collaborated with the Russian-aligned group NoName057(16) on large-scale DDoS attacks against an Israeli defense contractor and multiple municipal governments. Targeting also encompasses healthcare and health insurance organizations. Public attack announcements and coordinated coalition branding are central to its mobilization and messaging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned proxy-layer hacktivist group participating in the broader wartime disruption and propaganda ecosystem.
Pro-Iranian umbrella group coordinating multiple hacktivist groups and reportedly working with NoName057(16) on DDoS attacks against Israeli targets.
Umbrella hacktivist coordinator directing joint operations across Gulf states and Israel through a multi-group operations room.
Early hacktivist mobilization linked to the opening cyber phase of the Iran war.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.