Golden Falcon is a hacktivist-style threat actor that emerged during the March 2026 Iran-Israel-U.S. conflict and became notable for publishing geolocated targeting packages rather than primarily claiming disruptive attacks. The actor was observed releasing what appeared to be satellite imagery and location intelligence tied to sensitive sites, including military-related facilities inside Israel. Golden Falcon was later associated with a broader trend of systematic geolocation-based targeting that expanded beyond Israel to cover facilities and individuals across more than 10 countries. The actor’s activity centered on reconnaissance and target development. Reported targeting packages included nuclear facilities, offshore gas platforms, military air bases, refineries, and individual-level location data. This behavior indicates a focus on collecting, organizing, and publicizing operationally relevant intelligence that could support follow-on harassment, influence, or physical-world targeting by aligned actors. Golden Falcon is closely associated with the emergence of similar geolocation-driven activity later continued by Harvesting Time. Available information does not directly attribute Golden Falcon to a specific state, although its activity appeared within a broader ecosystem of pro-Iranian and anti-Israel cyber operations active during the conflict. High-confidence reporting supports characterization of Golden Falcon as an actor engaged in reconnaissance and doxxing-style exposure of location intelligence, with Israel among its confirmed targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unknown actor associated with systematic geolocated doxxing and reconnaissance packages against critical infrastructure and military-related targets across multiple countries.
Actor focused on publishing geolocation and imagery-based targeting intelligence on Israeli military infrastructure rather than disruptive attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.