Cyber Fattah is a pro-Iranian hacktivist group, also referred to in the content as Cyber Fattah Team, that describes itself as an "Iranian cyber team." Multiple sources in the content characterize it as Iranian-backed, affiliated, or activated by Iran, and one report places it among IRGC-linked operational groups alongside Bavar373 and Cyber Avengers. The group is also described as part of the broader Iran-aligned proxy and hacktivist ecosystem supporting Tehran’s wartime and ideological narratives, including the Axis of Resistance. SecurityScorecard additionally describes Cyber Fattah as a Palestinian-linked cell in the context of claimed data-dump operations. The content associates Cyber Fattah with reconnaissance, DDoS campaigns, website defacements, data theft, and hack-and-leak style activity. It is repeatedly described as using Telegram to rally participants, announce targets, claim attacks, and amplify narratives. During conflict periods, Cyber Fattah appeared in coalition activity with groups including Fatimion/Fatimiyoun Cyber Team or FAD Team, Cyber Islamic Resistance, 313 Team, DieNet, Sylhet Gang-SG, CJM, Keymous+, and MONARCH. The content also states that Cyber Fattah has collaborated with 313 Team and was among at least 60 hacktivist groups reportedly activated by Iran after U.S.-Israel attacks. Reported targeting in the content includes Israeli and Western web resources and government agencies, Israeli educational institutions, Channel 13 News in Israel, and Saudi interests. One report says pro-Iranian hacktivists such as Cyber Fattah targeted educational institutions in Israel and scanned Israeli-based network ranges for publicly exposed IoT devices. Another report states Cyber Fattah allegedly published thousands of personal records linked to athletes and visitors of the Saudi Games, with leaked material reportedly including IT staff credentials, government email addresses, passports or ID cards, bank statements, medical forms, and other scanned sensitive documents; Resecurity assessed that incident as part of an Iran-aligned information operation and said the data was believed to have been sourced from the Saudi Games 2024 official website via unauthorized access to phpMyAdmin. During the June 2025 Iran-Israel conflict, the group was described as conducting reconnaissance, DDoS, defacements, and data theft coordinated with military developments. The content also notes Cyber Fattah messaging around future operations: it published a statement saying planned attacks would follow after it finished collecting specific resources, and on March 22 it forwarded an APT IRAN post claiming a proof of concept for an alleged Lockheed Martin breach. The group’s branding is described as ideologically aligned with Tehran’s military-industrial narrative, with its name cited alongside Bavar373 and Stucx Team as deliberate signaling of allegiance to Iran.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
The pro-Iranian actors were also targeting popular Hikvision and Dahua cameras with a number of authentication and command-related vulnerabilities. The bugs they use include CVE-2017-7921, CVE-2021-36260, and CVE-2023-6895, and CVE-2025-34067 for Hikivision; and CVE-2021-33044 in the case of Dahua. Patches for all vulnerabilities are available now.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist actor contributing attack volume and propaganda amplification within the pro-Iran ecosystem.
Hacktivist group described as activated by Iran following the U.S.-Israel attacks.
Iranian-aligned hacktivist group participating in coordinated cyber activity during the 2026 Iran conflict.
Pro-Iranian hacktivist group targeting Israeli educational institutions and exposed IoT devices, including surveillance camera infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.