BABAYO EROR SYSTEM is a pro-Iranian or pro-Palestinian hacktivist entity publicly identified alongside groups such as AnonGhost and BD Anonymous during a surge of retaliatory cyber activity following the February 2026 U.S.-Israel military campaign against Iran. It has been associated with simultaneous targeting claims against Israel and the United States in the context of broader geopolitical cyber mobilization after the conflict. The group appears to operate in the hacktivist ecosystem rather than as a clearly documented state-directed intrusion set. In the observed period, hacktivist activity was characterized primarily by disruptive and propaganda-oriented operations, especially distributed denial-of-service attacks and website defacements, with generally low-to-medium sophistication. Although the wider campaign environment also included breach claims, data leak allegations, and initial-access sales by various actors, there is not enough high-confidence information to attribute those more advanced activities specifically to BABAYO EROR SYSTEM. Available information supports describing BABAYO EROR SYSTEM as a politically motivated actor aligned with anti-Israel and anti-U.S. narratives, participating in coordinated or parallel online operations during periods of regional escalation. No corroborated evidence in the available material establishes a nation-state affiliation, a distinct malware family, or a stable sub-group structure beyond the cited naming overlap with other hacktivist brands.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.