MOØN Badr is an unattributed threat cluster assessed to have conducted targeted espionage operations during the Q4 2025 to Q1 2026 period. The cluster has been distinguished from other contemporaneous Iran-related unattributed activity by its apparent limitation to espionage rather than destructive operations. Available reporting supports only a narrow characterization: MOØN Badr engaged in targeted intelligence collection, with no high-confidence evidence in the supplied facts of ransomware, extortion, disruptive attacks, or broader criminal monetization. Its tradecraft is therefore best characterized as focused post-compromise espionage activity rather than overt sabotage or financially motivated intrusion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.