Electronic Operations Room is a pro-Iranian hacktivist or state-aligned cyber persona that emerged during the rapid cyber escalation surrounding the February–March 2026 Iran crisis. It was identified alongside other pro-Iranian collectives and personas that collectively claimed more than 150 retaliatory cyber operations over a short period. The broader campaign environment included disruptive and destructive activity such as distributed denial-of-service attacks, website defacements, wiper malware deployment, ransomware, and claimed intrusions affecting industrial-control-related environments. Electronic Operations Room appears to operate within an ecosystem of ideologically aligned and potentially state-linked actors that included Handala Hack, Cyber Islamic Resistance, Dark Storm Team, and APT Iran. The available information supports characterization as a hacktivist or state-aligned actor rather than a clearly attributed standalone nation-state intrusion set. Reported targeting in the surrounding campaign spanned Israeli and Western organizations, including entities in energy, finance, healthcare, and other critical infrastructure sectors. High-confidence public detail on Electronic Operations Room specifically remains limited. Its inclusion among the actors claiming retaliatory operations indicates participation in coordinated or parallel influence-driven cyber activity associated with the conflict, but distinct tradecraft, malware families, victimology, and organizational structure are not currently available at sufficient confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.