Cyber Fattah Team
Cyber Fattah Team is a pro-Palestinian/pro-Iran-aligned hacktivist group active in cyberattacks and information warfare against Israeli infrastructure. The group is described as collaborating on Liwaa Mohammad Telegram channels (within the broader Cyber Islamic Resistance ecosystem). Reported activity includes claims of leveraging a functioning exploit for the critical React2Shell unauthenticated RCE vulnerability (CVE-2025-55182) affecting React Server Components/RSC Flight protocol for initial access. On 20 Dec 2025, the group claimed successful exploitation of React2Shell to deploy Baqiyat 313 Locker (BQTlock) ransomware at an Israeli-based victim and shared a screenshot consistent with use of a known proof-of-concept; the referenced victim was not listed on the BQTlock leak site (potentially indicating payment or non-publication). In broader Iran–Israel hacktivist activity (June 12–18, 2025), pro-Iranian groups—including those in the same ecosystem—primarily conducted DDoS, website defacement, and data breaches against Israeli government, military, and critical infrastructure, though reporting notes many hacktivist claims are often exaggerated and attribution is difficult.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇮🇱 Israel
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist collaborator that claims to exploit React2Shell (CVE-2025-55182) to gain initial access and deploy BQTLock ransomware against Israeli targets.
Engages in cyberattacks and information operations targeting Israeli infrastructure.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.