Iranian Avenger is a pro-Iran hacktivist persona that emerged or re-engaged during the regional escalation following the February 2026 U.S. and Israeli strikes on Iran. It has been identified alongside Cyber Toufan, Cyber Support Front, and Cyb3r Drag0nz as part of a wave of Iran-aligned online actors that amplified retaliatory messaging across social platforms and underground communities. Available reporting characterizes Iranian Avenger as a low-sophistication actor primarily associated with disruptive and influence-oriented activity rather than advanced intrusion operations. Its observed tradecraft is consistent with broader pro-Iran hacktivist behavior during the same period: public claims of attacks, narrative amplification, and participation in campaigns centered on website defacement, distributed denial-of-service activity, doxxing, leaks, and other often unverified or embellished compromise claims. The actor has also been observed in connection with the Electronic Operations Room of Islamic Resistance Axis, a team construct used by multiple Iran-aligned personas to coordinate or brand anti-Israeli cyber activity. No high-confidence evidence in the available reporting ties Iranian Avenger to sophisticated state-grade operations, bespoke malware development, or materially significant disruptive effects. The dominant pattern is politically motivated hacktivism aligned with Iranian interests and focused on retaliation, propaganda, and perceived adversaries, especially Israeli organizations and infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned persona observed operating through the Electronic Operations Room of Islamic Resistance Axis.
Pro-Iran hacktivist group that re-engaged or emerged during the conflict; associated generally with misinformation, incitement, and low-sophistication activity.
Emerging or reactivated pro-Iran group engaged mainly in unsophisticated tactics, embellished claims, and retaliatory messaging amplification.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.