Ghost Princess is a pro-Iranian, anti-Israel hacktivist persona or group active in Middle East cyber campaigns. It has also appeared as GhostPrincess, ghost_princess, and in association with TheGhostsITM. Reported activity places it among clusters that amplified anti-Israel operations, including #OpIsrael-style messaging, coordinated propaganda, and claimed disruptive cyber activity during periods of Iran-Israel escalation. The actor has been associated with information warfare and with claimed attacks against Israeli military, defense-adjacent, and utility targets. Across documented campaign periods, Ghost Princess has been grouped with other pro-Iranian hacktivist actors conducting denial-of-service attacks, website defacements, and claimed data-breach operations against Israeli government, military, and critical-infrastructure entities. Available reporting indicates that much of the surrounding hacktivist ecosystem relied on relatively low-complexity operations and frequently exaggerated operational impact, so specific success claims should be treated cautiously unless independently corroborated. Ghost Princess appears to operate primarily as an ideologically motivated hacktivist actor aligned with pro-Iranian and pro-Palestinian narratives rather than as a clearly established state unit. Its observed role includes online amplification, coordinated messaging, and participation in disruptive cyber campaigns targeting Israeli interests, especially during regional crises.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist persona/group amplifying #OpIsrael messaging, coordinating narratives across GCC states, and promoting threats against Israeli utilities and defense-adjacent entities.
Targets Israeli military and defense systems with information warfare and cyberattacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.