Electronic Operations Room of Islamic Resistance Axis is an Iran-aligned hacktivist coordination team that emerged in late February 2026 amid heightened regional conflict involving Iran and Israel. It has been described as a larger umbrella team through which multiple pro-Iran personas operate, including Cyb3r Drag0nz, with an expressed aim of disrupting Israeli organizations and infrastructure. The cluster appears to be part of a broader ecosystem of pro-Iran online actors active across social media and messaging platforms, where operations have included propaganda amplification, retaliatory messaging, and claimed cyber activity tied to the conflict. Available reporting indicates that this team is associated with low-sophistication hacktivist operations rather than advanced state-grade intrusion tradecraft. The wider campaign environment in which it operates has been characterized by website defacements, distributed denial-of-service activity, doxxing, leaks, and unverified compromise claims against Israeli entities. High-confidence evidence directly tying the team to specific advanced intrusions, destructive malware, or materially significant operational impact is not currently available. Its dominant role appears to be coordination, mobilization, and narrative-driven disruptive activity within the pro-Iran hacktivist landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Umbrella Iran-aligned team coordinating multiple personas involved in disruptive and influence-style cyber operations.
Named larger team or activity cluster focused on disrupting Israeli organizations and infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.