Fatimion Cyber Team
Fatimion Cyber Team is an Iranian-aligned or Iranian-backed hacktivist group referenced as part of Iran’s broader proxy cyber ecosystem. The available content places it alongside groups such as Cyber Islamic Resistance and Cyber Fattah and describes it as participating in operations coordinated with military developments during the June 2025 Israel-Iran conflict and the wider 2025-2026 regional escalation. Reported activity attributed to the group includes reconnaissance, DDoS campaigns, website defacements, and data theft. One cited example states that Fatimion Cyber Team attacked Israeli Air Force and Israeli government sites. The group is also listed among participants in Iranian-aligned campaigns coordinated through the Islamic Resilience Cyber Axis / Electronic Operations Room during the 2026 conflict. The content characterizes many Iranian-aligned hacktivist operations as low-to-medium sophistication and notes that synchronized timing, target selection, and sharing of vulnerabilities and attack scripts among such groups suggested orchestration and institutional backing rather than purely organic hacktivism. No additional verified aliases or sub-groups for Fatimion Cyber Team are provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇮🇱 Israel
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian-aligned hacktivist group involved in coordinated cyber operations during the 2026 Iran conflict against US, Israeli, and GCC targets.
Iranian-aligned hacktivist group identified as a key player in the escalation, involved in reconnaissance, DDoS campaigns, website defacements, and data theft.
An Iranian-backed or affiliated hacktivist group observed during the June 2025 Israel-Iran conflict conducting coordinated cyber operations aligned with military developments.
Targets Israeli military and government systems.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.