Nasir Security is a relatively new Iran-aligned threat actor and hacktivist-style cyber operation focused primarily on Middle Eastern energy organizations and their supply chains. The group is also referred to as Nasir Resistance and Al-Nasir Resistance, and has used shifting self-identifications including references to Hezbollah and Al-Nusayr, indicating unstable branding and strong ideological messaging. Available reporting supports an assessment of pro-Iranian alignment, but direct state control is not established with high confidence. The actor has concentrated on oil, gas, and related energy-sector targets in the Gulf, including organizations in the United Arab Emirates, Oman, Iraq, and Saudi Arabia. Reported activity indicates that Nasir Security often targets third-party vendors and contractors supporting these firms, especially companies involved in engineering, construction, and safety services, rather than directly compromising the named energy operators themselves. Stolen material has included authentic business documents such as contracts, schemes, maps, and risk assessment reports. Such information could support follow-on targeting of operational environments, oil fields, and pipeline infrastructure by revealing dependencies, equipment, and other sensitive contextual details. Nasir Security has been associated with business email compromise, spearphishing, impersonation, exploitation of public-facing applications, and theft of data from insecure cloud storage. The group also conducts data exfiltration and public leak operations, using authentic third-party documents to amplify claims of larger breaches and to create reputational confusion around victim attribution. Reporting indicates that its public claims have at times substantially overstated the scale or directness of compromise. Some named victims reportedly were not extorted, and the actor’s behavior is more consistent with propaganda, psychological pressure, and geopolitical signaling than with conventional profit-driven ransomware operations. The group has also been linked to alleged data leaks involving Dubai International Airport, where exposed personal data reportedly included traveler-related imagery and identity documents. Across observed operations, Nasir Security appears to combine intrusion activity with influence-oriented messaging intended to magnify perceived impact. Its tradecraft and victimology place it within the broader ecosystem of Iran-aligned cyber activity targeting strategically important regional sectors during periods of geopolitical tension.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist data-leak operation exposing allegedly stolen Dubai International Airport data, including passport photos and security-related images.
A relatively new cybercriminal group conducting supply-chain attacks against Middle East energy-sector vendors; activity is assessed as likely carried out by cyber-mercenaries or individuals hired or sponsored by Iran or its proxies.
Iran-aligned hacktivist group that claimed breaches of Middle Eastern oil and gas companies, but reporting indicates it actually targeted related supply chain vendors and used stolen contractor documents to exaggerate impact and shape narratives.
Targeting Middle East energy organizations and their supply chain vendors to steal authentic documents such as schemes, contracts, and risk assessment reports, likely to support further targeting and pre-positioning against oil and gas infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.