Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors
🇮🇷 IR

Soldiers of Solomon

Also known assoldiers_of_solomon

Soldiers of Solomon is an Iran-linked cyber persona/group associated with the Islamic Revolutionary Guard Corps (IRGC) ecosystem. The content describes it as connected to CyberAv3ngers and other IRGC-linked personas, and Microsoft reporting cited in the content says Storm-784 runs personas including Cyber Avengers and Soldiers of Solomon. It is part of a broader set of Iran-aligned hacktivist or proxy groups used for cyber-enabled influence operations and plausible deniability. The group/persona has been used on Telegram and X/Twitter to claim attacks against Israeli military and critical infrastructure. The content states that in at least one case, Soldiers of Solomon was a persona adopted by Iranians on Telegram to make claims about attacking Israeli military infrastructure; Microsoft assessed they were able to carry out a ransomware attack, but that their claims about the precision and impact of the operation were overstated. This aligns with the broader pattern described in the content of Iranian operations pairing real but often limited cyber activity with information operations intended to exaggerate impact, create confusion, and amplify psychological effects. Known associations and aliases directly mentioned in the content are limited to the name Soldiers of Solomon itself, plus its linkage to CyberAv3ngers/Cyber Avengers and Microsoft-tracked Storm-784. The content does not provide additional confirmed sub-groups or distinct aliases beyond those associations.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Utilities
  • Energy
  • Transportation
  • Health Care Equipment & Services
  • Food, Beverage & Tobacco

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇮🇱 Israel
  • 🇬🇧 United Kingdom

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics15 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1078
Valid Accounts
T1078.001
Default Accounts
TA0003
Persistence
1 technique
T1078
Valid Accounts
T1078.001
Default Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
T1078.001
Default Accounts
TA0005
Stealth
1 technique
T1078
Valid Accounts
T1078.001
Default Accounts
TA0006
Credential Access
1 technique
T1110
Brute Force
TA0040
Impact
4 techniques
T1491
Defacement
T1491.001
Internal Defacement
T1499×2
Endpoint Denial of Service
T1531
Account Access Removal
T1565
Data Manipulation
T1565.001
Stored Data Manipulation
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.