313 Team, also known as Islamic Cyber Resistance in Iraq, is an Iraq-based, pro-Iran hacktivist and resistance-branded disruption actor operating within the broader Iran-aligned cyber proxy ecosystem. The group is associated with coalition-style operations coordinated through Telegram and has been described as an affiliate or participant in the Cyber Islamic Resistance milieu alongside other pro-Iran and opportunistic actors. Its activity is characterized by high-volume, low-to-moderate sophistication disruptive operations, symbolic targeting, propaganda amplification, and coercive messaging rather than advanced intrusion tradecraft. The group is primarily known for distributed denial-of-service operations against public-facing services, especially government portals, major online platforms, and high-visibility symbolic targets. Reported targeting has included government entities in Gulf states, social media platforms, e-commerce services, open-source software infrastructure, and other organizations associated with countries viewed as aligned with the United States or Israel. During the 2026 Iran-related conflict surge, 313 Team was repeatedly identified as one of the most active actors by incident volume and as a central node in coalition campaigns spanning multiple countries. 313 Team has claimed or been linked to disruptive campaigns against Jordanian, Kuwaiti, Emirati, Australian, Israeli-linked, U.S.-linked, and UK-linked targets, as well as attacks affecting Canonical and Ubuntu infrastructure, Bluesky, and eBay. In the Canonical/Ubuntu case, the group paired service disruption with extortion-style demands, threatening continued attacks unless the victim engaged, indicating that its operations can blur from hacktivism into coercive disruption. The actor has also been associated with use of commercial DDoS-for-hire infrastructure, including Beamed, illustrating reliance on outsourced attack capacity to generate outsized operational impact. Tradecraft attributed to 313 Team centers on DDoS, symbolic target selection, public claims of responsibility, Telegram-based propaganda, coalition amplification, and intimidation messaging. Broader reporting also associates the group with defacement, phishing, and data-leak claims, though its most consistently corroborated capability is disruptive DDoS activity. Assessments of the wider ecosystem note frequent exaggeration of impact and the need to distinguish verified outages from propaganda claims. The group’s operational role appears to be sustained nuisance and pressure operations that create visibility, psychological effect, and cumulative disruption during geopolitical crises. Known aliases include Islamic Cyber Resistance in Iraq and Islamic Cyber Resistance. The actor is widely assessed as Iraq-based and aligned with pro-Iranian interests, likely functioning as part of a deniable proxy layer rather than as a top-tier state intrusion unit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Launching disruptive and extortion-oriented attacks against Canonical and Ubuntu infrastructure using a DDoS-for-hire service, causing outages to official websites and Ubuntu’s security API.
Iran-aligned disruption actor using DDoS, propaganda, and symbolic targeting; noted for participation in the May 2026 Canonical/Ubuntu disruption.
Claimed responsibility for a distributed denial-of-service attack against Canonical, disrupting Ubuntu download and update mirrors, the main website, Launchpad, the Snap store, and Canonical SSO.
Pro-Iran hacktivist group conducting sustained DDoS attacks and appearing to shift toward extortion by demanding Canonical contact them or face continued disruption. The group also claimed similar DDoS attacks against eBay Japan, eBay US, and BlueSky.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.