DieNet Network is a pro-Iranian hacktivist cluster associated with large-scale distributed denial-of-service activity during the 2026 Middle East conflict escalation following U.S.-Israeli strikes on Iran. The group was identified as leading disruptive campaigns framed as retaliation for Operation Epic Fury and was active against government portals, telecommunications providers, airports, and financial institutions. Reported targeting spanned Bahrain, Qatar, the United Arab Emirates, Kuwait, Saudi Arabia, and the United States, indicating both regional and extra-regional spillover. The actor’s observed tradecraft is centered on disruption rather than covert intrusion or financially motivated extortion. High-confidence reporting links the group to volumetric service-denial operations against public-facing services in government, telecom, aviation, and finance. DieNet Network has also been referenced as DieNet Network V5. Available information supports characterization as a politically aligned hacktivist actor operating in support of Iranian interests during a period of hybrid conflict, rather than as a ransomware or espionage-focused threat group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Iranian hacktivist group conducting large-scale retaliatory DDoS operations against government, telecom, airport, and financial targets.
Hacktivist group conducting/claiming large-scale retaliatory DDoS campaigns aligned with pro-Iran narratives, targeting government, telecom, aviation, and financial services across GCC states and the US.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.