Anonymous Syria Hackers is an anti-Iran, pro-Israel counter-hacktivist group active in the Middle Eastern conflict-driven cyber ecosystem. The group has been identified targeting Iranian government channels, state media, propaganda outlets, government infrastructure, and entities linked to the Islamic Revolutionary Guard Corps. Reported targeting has included Iranian state media organizations and other infrastructure associated with the Iranian state and its loyalist networks. The group’s publicly claimed operations center on disruptive and data-exposure activity rather than advanced stealth tradecraft. Attributed behavior includes intrusions followed by publication of stolen data, with operations framed as part of broader anti-Iran campaigns such as #Op_Iran. Anonymous Syria Hackers has also been listed alongside other anti-Iran actors including Anonymous OpRan, Black Wolves, Krypr Team, Official Legion, Islamic Hacker Army, and Predatory Sparrow in campaigns directed at Iranian interests. Available reporting characterizes Anonymous Syria Hackers primarily as a hacktivist or counter-hacktivist actor rather than a confirmed state unit. Its operations appear politically and ideologically motivated, aligned with opposition to the Iranian government and support for Israeli interests. Although some reporting notes that anti-Iran groups in this ecosystem may include state-sponsored elements, no high-confidence attribution establishes Anonymous Syria Hackers itself as a state-sponsored organization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Israel counter-hacktivist group targeting Iranian government, propaganda, and IRGC-linked infrastructure.
Pro-Israel actor conducting breach-and-leak operations against Iranian targets, including educational and e-commerce entities, and publishing stolen credential and personal data claims.
Anti-Iran Syrian opposition-aligned group targeting Iranian state media, government infrastructure, and IRGC-linked entities.
Anonymous Syria Hackers is a hacktivist group targeting Iranian organizations, likely using DDoS and data leak tactics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.