313 Team, also known as 313 and the Islamic Cyber Resistance in Iraq, is an Iraq-based, pro-Iranian hacktivist collective that also uses the Iraqi Cyber Army branding. Its ideological messaging emphasizes the Islamic Resistance and Palestinian solidarity. It participates in a broader Iran-aligned hacktivist coalition, coordinating disruptive campaigns and amplifying allied groups’ messaging. Its political alignment does not establish Iranian state direction or control. The group primarily conducts distributed denial-of-service attacks and website defacements, with targeting focused on public-facing government services and high-visibility commercial platforms. Its campaigns have targeted Israel, Gulf states, Jordan, and Western-linked organizations. Telegram is central to its operations and publicity, supported by backup channels, leak-oriented channels, and an X presence. It uses these platforms to announce targets, circulate attack claims, display defacements, and maintain continuity following account removals. In May 2026, 313 Team conducted a disruptive campaign against Canonical and Ubuntu infrastructure. Canonical confirmed a sustained cross-border DDoS attack that interrupted public websites, downloads, and account access. The group paired the disruption with demands for contact and payment, threatening continued attacks unless Canonical negotiated. This demonstrates its use of DDoS extortion alongside ideologically motivated disruption. The group’s established operational profile centers on availability attacks, symbolic targeting, and coalition publicity rather than sophisticated intrusion tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Third-party group to which BLACKNET-00 reportedly offered its tools.
Hacktivist and claimed ransomware operations combining website defacements, propaganda, leak-channel activity, extortion-style victim messaging, and promotion of a purported '313 Ransomware' capability.
Iraqi-nexus group identified as a prospective or claimed user of TRK-25 ICS/SCADA tooling. Its claimed use of the tool against a US news agency is unverified.
Launching disruptive and extortion-oriented attacks against Canonical and Ubuntu infrastructure using a DDoS-for-hire service, causing outages to official websites and Ubuntu’s security API.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.