DieNet is a pro-Iranian, pro-Palestinian hacktivist group that emerged on Telegram around March 2025. It is described as one of the most prolific disruptive actors in the 2026 Iran-Israel conflict and broader Middle East cyber activity, functioning primarily as a high-volume DDoS collective and propaganda brand rather than a stealth intrusion actor. Known aliases include DieNet, DieNet-v2, and later referenced iterations up to DieNet-v5. The group has also been described as part of the looser Iran-aligned proxy layer and as operating through or alongside the Cyber Islamic Resistance / Electronic Operations Room coalition with other Iran-aligned personas including APTIran, Cyber Toufan, Cyber Support Front, Iranian Avenger, and Cyb3r Drag0nz. DieNet’s core confirmed activity is disruptive network attacks, especially DDoS. Reporting describes it as a primary DDoS infrastructure supplier and toolkit provider for allied hacktivist groups, providing structured target lists and automated check-host verification. Its claimed attack repertoire includes TCP RST floods, TCP SYN floods, DNS amplification, NTP amplification, and Layer 7 application attacks, and its primary confirmed MITRE ATT&CK technique is Network Denial of Service (T1498). Multiple sources characterize DieNet as a central node in hacktivist coalitions and a primary volume driver for pro-Iranian campaigns. During the late February to early March 2026 Middle East escalation, Radware reported that Keymous+ and DieNet drove nearly 70 percent of activity, and that Keymous+, DieNet, and NoName057(16) accounted for 74.6 percent of global claims in the three-day window. Separate reporting states DieNet recorded 59 attack claims during March 2-3, 2026 and claimed more than 100 attacks against more than 50 Israeli websites in a single day under its #CanYouResist operation. The group has targeted government, finance, telecommunications, transportation, utility, civilian, and other critical infrastructure-related entities. Reported targets span Israel, the United States, Kuwait, Bahrain, Jordan, Saudi Arabia, the United Arab Emirates, Qatar, Cyprus, India, and Egypt. Named targets in reporting include Israeli government and e-government resources, NSO Group, Hadassah Zedek Medical Center, Kuwait’s Armed Forces website, Ministry of Defense, Ministry of Electricity and Water, Kuwait Airport, Bahrain Airport, Batelco, Abu Dhabi Digital Authority, Sharjah Airport, Ras Al Khaimah Airport, Qatar’s e-Government Portal, and Jordanian public-sector entities. Earlier U.S.-focused claims included attacks against transit, energy, healthcare, finance, and technology organizations. Reporting also states DieNet and allied groups systematically targeted Gulf states perceived as politically aligned with Israel or the United States, specifically Jordan, Saudi Arabia, Bahrain, and Kuwait. DieNet is repeatedly described as aligned with broader Iran-linked hacktivist ecosystems and coalition activity. It has been listed alongside groups such as 313 Team, Dark Storm Team, Cyber Islamic Resistance, Fatimion Cyber Team, FAD Team, Sylhet Gang-SG, and Handala-related ecosystems. Some reporting states DieNet and 313 Team acted as central nodes orchestrating simultaneous DDoS campaigns across multiple GCC states. One source says DieNet is believed to include Russian-speaking members and connections to cyber communities in Eastern Europe. Although DieNet has claimed ransomware, data theft, exfiltration, and OT/ICS access, the content consistently notes that many of these more advanced claims are unverified, exaggerated, or likely inflated for psychological effect. This includes claimed OT/ICS and PLC access screenshots and a claimed ransomware strain called Locknet. A reported 247 GB exfiltration claim against India’s National Informatics Centre was assessed by CloudSEK as mostly publicly available material. Overall, the content supports high confidence that DieNet is a disruptive, Telegram-coordinated, Iran-aligned hacktivist actor whose principal operational role is politically timed, high-volume DDoS activity and coalition amplification.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist actor in the pro-Iran/Axis-aligned ecosystem contributing high attack volume, rhetoric, target lists, and claims amplification during crisis-driven campaigns.
Iran-aligned persona operating through the Electronic Operations Room of Islamic Resistance Axis; specifically claimed DDoS attacks against airports and banks.
Hacktivist support network and toolkit provider supplying DDoS capability, target lists, and automated verification for Gulf-focused operations.
Named DDoS-focused group involved in targeting Cyprus during the conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.