Conquerors Electronic Army (CEA) is a pro-Iran, resistance-branded hacktivist group active in the cyber campaigns that accompanied the 2026 Iran-Israel-U.S. conflict. It has been described as operating under the Cyber Islamic Resistance umbrella and aligning with broader Iranian and Axis of Resistance narratives. Within that ecosystem, the group appears to function primarily as a disruptive and propaganda-amplification actor rather than a sophisticated intrusion operator. CEA is associated chiefly with distributed denial-of-service activity against Israeli and other adversary-linked targets. Reported targeting includes Israeli commercial and military-related online resources, as well as at least one U.S.-based commercial platform. It has also been counted among the more active pro-Iranian hacktivist groups during the 2026 escalation, though still below the highest-volume actors such as Keymous+ and DieNet. Its operations fit a broader pattern of loosely coordinated Telegram-based mobilization in which aligned groups share target lists, amplify one another’s claims, and contribute symbolic disruption intended to create psychological pressure and public visibility. The group’s known tradecraft is low sophistication and centers on nuisance-level disruption, especially DDoS, accompanied by propaganda messaging and public claim amplification. It has been explicitly grouped with other actors whose main contribution to the coalition was DDoS activity rather than destructive intrusion, ransomware, or advanced espionage. Available reporting does not support attribution of higher-end capabilities to CEA beyond disruptive operations and messaging support.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of the coalition contributing DDoS activity and propaganda amplification.
Iran-aligned group conducting low-level disruptive activity during the ceasefire period, including claimed DDoS attacks against Israeli targets and the US-based Upwork platform.
Named as a pro-Iranian hacktivist group active during the March 2026 escalation, associated with attack claim activity.
Group involved in DDoS attempts against Israeli military resources during the conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.