313 Team, also referred to as the Islamic Cyber Resistance in Iraq and sometimes Unit 313/UniT 313, is an Iraq-based, Iran-aligned hacktivist/disruption actor and affiliate of the Cyber Islamic Resistance ecosystem. The reporting describes it as part of a looser proxy layer within the broader pro-Iran cyber ecosystem rather than a traditional state APT. It is repeatedly characterized as resistance-branded and focused primarily on distributed denial-of-service (DDoS) operations, Telegram-based propaganda, symbolic targeting, coalition amplification, and, in some reporting, defacement and data leak claims. Content also places it among Iraqi Shia militia-aligned cyber groups in the Iraq-Iran cyber corridor and notes that such groups frame operations as retaliation aligned with the Axis of Resistance. The actor is described as one of the most active groups in the 2026 Iran-related cyber conflict, with one report attributing 222 incidents to it and identifying it as the single most active actor in that period. Reporting states that 313 Team and DieNet acted as central nodes in hacktivist coalitions, orchestrating simultaneous DDoS campaigns across multiple GCC states. Mentioned targeting includes government portals and e-government services in Jordan, Kuwait, the UAE, Saudi Arabia, Israel, and the United States, as well as broader multi-country targeting claims involving Australia and symbolic or high-visibility online platforms. Specific operations mentioned in the content include claimed disruptive attacks against Jordanian government infrastructure; a coordinated assault on 26 Kuwaiti government domains and Kuwait’s e-government portal; a coordinated DDoS campaign against 20 UAE government domains; claimed attacks against Microsoft cloud services; and a claimed attack on an Australian government authentication portal. The group also claimed responsibility for disruptive attacks against public-facing platforms and companies including Ubuntu/Canonical, Bluesky, Truth Social, archive.org, and eBay. In the Canonical/Ubuntu case, reporting states Canonical confirmed a sustained cross-border DDoS attack affecting Ubuntu.com and related services, while 313 Team claimed responsibility via Telegram and later issued a coercive follow-up demanding contact, which reporting assessed as a shift toward extortion. Bluesky reporting says the group claimed responsibility for a sophisticated DDoS attack, while Bluesky stated it found no evidence of unauthorized access to private user data. The content consistently associates 313 Team with low-level to nuisance-level disruptive activity rather than elite tradecraft, while also noting that such activity can still create operational and narrative impact during geopolitical crises. Known aliases directly mentioned in the content are Islamic Cyber Resistance in Iraq, 313 Team, and Unit 313/UniT 313.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned disruption actor using DDoS, propaganda, and symbolic targeting; noted for participation in the May 2026 Canonical/Ubuntu disruption.
Claimed responsibility for a distributed denial-of-service attack against Canonical, disrupting Ubuntu download and update mirrors, the main website, Launchpad, the Snap store, and Canonical SSO.
Pro-Iran hacktivist group conducting sustained DDoS attacks and appearing to shift toward extortion by demanding Canonical contact them or face continued disruption. The group also claimed similar DDoS attacks against eBay Japan, eBay US, and BlueSky.
Claimed responsibility for a large-scale DDoS attack that disrupted eBay and warned of similar attacks against other globally recognized businesses as part of a broader campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.