Ababil of Minab
Ababil of Minab is a pro-Iranian threat actor persona that surfaced in late March 2026 and claimed destructive intrusions against targets in the United States, Israel, Saudi Arabia, and Turkey. The group is most prominently associated with the March 2026 breach of the Los Angeles County Metropolitan Transportation Authority (LACMTA), for which it claimed responsibility on April 9, 2026, asserting that it stole and deleted data and publishing screenshots, video, and claims on Telegram and its website. Supporting reporting states that LACMTA confirmed a breach, and that the incident disrupted parts of the transit network, including some arrival screens and transit card funding functions, though rail and bus operations continued. Multiple cited reports, especially from Gambit Security, assess with high confidence that Ababil of Minab is not an independent hacktivist group but a front persona tied to Iran’s Ministry of Intelligence and Security (MOIS). The content explicitly states that Ababil of Minab, along with Handala Hack Team, is one of several front personas operated by MOIS. Gambit Security further linked the activity to the Iranian threat cluster tracked as Black Shadow, and some reporting also references overlap with activity tracked as MuddyWater and Static Kitten. Hunt.io reported exposed staging infrastructure and recovered victim data and tooling, but stated it did not independently verify Gambit’s attribution. The actor’s operations combined destructive actions with systematic exfiltration. Reported destructive techniques included SQL Server deletion, virtual machine deletion through vCenter, manual partition deletion through Disk Management, storage volume formatting, Veeam backup destruction, file system damage, and deletion of backup files. The content states the operators used both scripted automation and hands-on-keyboard activity. In the Vyncs intrusion, a custom Python script reportedly iterated through a hardcoded list of SQL Server instances and dropped user databases; the content also states the operators used ChatGPT to refine that script. Against LA Metro, published material and reporting indicate access to VMware vCenter, Microsoft IIS servers, and a rail yard management/train control display system. The group also used Telegram to publicize claims and threats. The content describes custom tooling associated with the campaign, including a Flask-based encrypted upload receiver and a bespoke C++ exfiltration tool named FileFiend. Hunt.io reported an exposed staging server containing exfiltrated data, shell history, TLS certificate files, and evidence of transfers from infrastructure previously linked to nefeshhope[.]com, an Iranian phishing operation targeting IDF soldiers in 2025. Beyond LACMTA, the content says Ababil of Minab claimed or was linked to attacks affecting South Florida’s Tri-Rail commuter transit system, vehicle tracking company Vyncs, and Saudi company UNIMAC. Additional victims identified in reporting included an Israeli media organization, an Israeli educational institution, a Turkish insurance brokerage, and other organizations in sectors including culture, digital services, restaurants, and news. In several of those additional cases, the content notes evidence of exfiltration without confirmed destructive activity. Known alias in the provided content: Ababil of Minab. Related MOIS-linked front persona mentioned in the content: Handala Hack Team. Related attributed cluster names mentioned in the content: Black Shadow, MuddyWater, Static Kitten.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Software & Services
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive intrusion and data exfiltration campaign targeting organizations in the United States, Israel, Saudi Arabia, and Turkey, including transportation, academia, media, and insurance entities. The group used exposed staging servers, custom upload tooling, credential theft, archive-based exfiltration, and destructive wiping actions.
Iran MOIS front persona associated with wiper attacks, targeting senior officials, and doxxing activity.
Destructive and data-theft campaign targeting transportation and other organizations, including LA Metro, using scripted and hands-on-keyboard deletion of virtual machines, partitions, and databases while presenting itself as a hacktivist persona.
Conducted a destructive intrusion against LACMTA involving data exfiltration and destruction of infrastructure, and was also linked to additional intrusions affecting organizations in Israel, Turkey, Saudi Arabia, and other sectors. The group is described as tied to Iran's MOIS while presenting itself as a standalone hacktivist crew.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.