Skip to main content
Mallory
2 malware families

Predatory Sparrow

Also known asgonjeshke_darandePredatory Sparrow

Predatory Sparrow, also known as Gonjeshke Darande, is a pro-Israel threat actor that has conducted disruptive and destructive cyber operations against Iranian targets since at least 2021. Multiple sources in the provided content describe it as a purported hacktivist group, while also noting suspected state links and frequent public assessment that it is linked to Israel; some reporting specifically describes it as a suspected Israeli nation-state threat actor posing as an Iranian opposition hacktivist group, but the evidence on direct government control is described as inconclusive. The group has at times claimed to be an Iranian entity defending Iranian citizens against the Islamic Republic. Additional aliases mentioned in the content are Adalat Ali, Indra, and MeteorExpress. The group is associated in the content with operations against Iranian rail assets in 2021, Iran’s fuel distribution system in October 2021, Iranian state media infrastructure in 2021, an Iranian steel facility in June 2022 that reportedly caused a serious fire, petrol distribution infrastructure in 2021 and 2023, Bank Sepah in June 2025, and the Nobitex cryptocurrency exchange in June 2025. Reported impacts include widespread outages affecting banking and payment services, disruption to fuel stations, destruction or wiping of data, publication of source code and internal documentation, and destructive handling of stolen cryptocurrency. In June 2025, Predatory Sparrow claimed responsibility for a cyberattack on Bank Sepah, accusing the bank of helping fund Iran’s military, terrorist proxies, ballistic missile program, and military nuclear program. The operation reportedly caused widespread service outages that prevented customers from accessing accounts, withdrawing cash, or using bank cards, and also affected gas stations relying on the bank’s payment infrastructure. The content states the claimed destruction of Bank Sepah data is consistent with the group’s past use of wiper malware. One day later, the group claimed it breached Nobitex, Iran’s largest cryptocurrency exchange, stealing roughly $90 million in digital assets. The content states the funds were sent to vanity addresses containing variations of anti-IRGC phrases, effectively burning the assets, and that Predatory Sparrow also posted Nobitex source code and internal documentation on X. The group claimed Nobitex was central to the Iranian regime’s sanctions evasion and terror financing efforts. Earlier operations attributed or claimed by Predatory Sparrow in the content include the October 2021 attack on Iran’s fuel distribution system, which disrupted subsidized fuel card processing and affected thousands of gas stations, with messages such as "cyberattack 64411" and protest-themed billboard text appearing on affected systems. The group also claimed a June 27, 2022 attack on an Iranian steel production facility that reportedly caused a serious fire. Across the provided content, Predatory Sparrow is characterized as capable of sophisticated, coordinated operations over several years, with disciplined messaging and a focus on Iranian critical infrastructure and financial systems.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Financial Services

Where they target

Geographies tied to known operations.

  • 🇮🇷 Iran
MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

3 of 15 tactics13 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1200
Hardware Additions
TA0010
Exfiltration
3 techniques
T1020
Automated Exfiltration
T1041
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
T1567.001
Exfiltration to Code Repository
TA0040
Impact
7 techniques
T1485×3
Data Destruction
T1489
Service Stop
T1498
Network Denial of Service
T1499
Endpoint Denial of Service
T1561
Disk Wipe
T1561.001
Disk Content Wipe
T1565×2
Data Manipulation
T1657
Financial Theft
ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Predatory Sparrow | Mallory