Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇮🇷 IR1 malware family

Ababil of Minab

Also known asAbabil of Minab

Ababil of Minab is a pro-Iranian threat actor persona that surfaced in late March 2026 and claimed destructive intrusions against targets in the United States, Israel, Saudi Arabia, and Turkey. The group is most prominently associated with the March 2026 breach of the Los Angeles County Metropolitan Transportation Authority (LACMTA), for which it claimed responsibility on April 9, 2026, asserting that it stole and deleted data and publishing screenshots, video, and claims on Telegram and its website. Supporting reporting states that LACMTA confirmed a breach, and that the incident disrupted parts of the transit network, including some arrival screens and transit card funding functions, though rail and bus operations continued. Multiple cited reports, especially from Gambit Security, assess with high confidence that Ababil of Minab is not an independent hacktivist group but a front persona tied to Iran’s Ministry of Intelligence and Security (MOIS). The content explicitly states that Ababil of Minab, along with Handala Hack Team, is one of several front personas operated by MOIS. Gambit Security further linked the activity to the Iranian threat cluster tracked as Black Shadow, and some reporting also references overlap with activity tracked as MuddyWater and Static Kitten. Hunt.io reported exposed staging infrastructure and recovered victim data and tooling, but stated it did not independently verify Gambit’s attribution. The actor’s operations combined destructive actions with systematic exfiltration. Reported destructive techniques included SQL Server deletion, virtual machine deletion through vCenter, manual partition deletion through Disk Management, storage volume formatting, Veeam backup destruction, file system damage, and deletion of backup files. The content states the operators used both scripted automation and hands-on-keyboard activity. In the Vyncs intrusion, a custom Python script reportedly iterated through a hardcoded list of SQL Server instances and dropped user databases; the content also states the operators used ChatGPT to refine that script. Against LA Metro, published material and reporting indicate access to VMware vCenter, Microsoft IIS servers, and a rail yard management/train control display system. The group also used Telegram to publicize claims and threats. The content describes custom tooling associated with the campaign, including a Flask-based encrypted upload receiver and a bespoke C++ exfiltration tool named FileFiend. Hunt.io reported an exposed staging server containing exfiltrated data, shell history, TLS certificate files, and evidence of transfers from infrastructure previously linked to nefeshhope[.]com, an Iranian phishing operation targeting IDF soldiers in 2025. Beyond LACMTA, the content says Ababil of Minab claimed or was linked to attacks affecting South Florida’s Tri-Rail commuter transit system, vehicle tracking company Vyncs, and Saudi company UNIMAC. Additional victims identified in reporting included an Israeli media organization, an Israeli educational institution, a Turkish insurance brokerage, and other organizations in sectors including culture, digital services, restaurants, and news. In several of those additional cases, the content notes evidence of exfiltration without confirmed destructive activity. Known alias in the provided content: Ababil of Minab. Related MOIS-linked front persona mentioned in the content: Handala Hack Team. Related attributed cluster names mentioned in the content: Black Shadow, MuddyWater, Static Kitten.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Software & Services

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics45 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1078×3
Valid Accounts
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.006×2
Python
TA0003
Persistence
1 technique
T1078×3
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
TA0005
Stealth
2 techniques
T1036
Masquerading
T1036.005
Match Legitimate Resource Name or Location
T1078×3
Valid Accounts
TA0112
Defense Impairment
1 technique
T1578×2
Modify Cloud Compute Infrastructure
T1578.003
Delete Cloud Instance
TA0006
Credential Access
2 techniques
T1552
Unsecured Credentials
T1552.001
Credentials In Files
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
2 techniques
T1083
File and Directory Discovery
T1135×2
Network Share Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001
Remote Desktop Protocol
TA0009
Collection
5 techniques
T1005
Data from Local System
T1039
Data from Network Shared Drive
T1074
Data Staged
T1119
Automated Collection
T1560×2
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.003
Multi-hop Proxy
T1102
Web Service
T1105×2
Ingress Tool Transfer
TA0010
Exfiltration
5 techniques
T1020
Automated Exfiltration
T1041×5
Exfiltration Over C2 Channel
T1048×2
Exfiltration Over Alternative Protocol
T1537
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
T1567.002×2
Exfiltration to Cloud Storage
TA0040
Impact
6 techniques
T1485×11
Data Destruction
T1486×3
Data Encrypted for Impact
T1490×3
Inhibit System Recovery
T1491
Defacement
T1561
Disk Wipe
T1561.001
Disk Content Wipe
T1561.002
Disk Structure Wipe
T1565
Data Manipulation
T1565.001
Stored Data Manipulation
IOCS

Observables

10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

huntio blogNews
Jun 18, 2026
Ababil of Minab Exposed: LA Metro SCADA Backups and Israeli Victim Data Left Open on an Iranian Staging Server

Destructive intrusion and data exfiltration campaign targeting organizations in the United States, Israel, Saudi Arabia, and Turkey, including transportation, academia, media, and insurance entities. The group used exposed staging servers, custom upload tooling, credential theft, archive-based exfiltration, and destructive wiping actions.

Read more
palo alto networks unit 42 blogNews
May 28, 2026
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

Iran MOIS front persona associated with wiper attacks, targeting senior officials, and doxxing activity.

Read more
security affairsNews
May 27, 2026
The LA Metro Attack Wasn't Hacktivism. It Was a State Operation With a Costume On.

Destructive and data-theft campaign targeting transportation and other organizations, including LA Metro, using scripted and hands-on-keyboard deletion of virtual machines, partitions, and databases while presenting itself as a hacktivist persona.

Read more
the record mediaNews
May 27, 2026
Iranian intelligence service behind hack of LA transit system, researchers say | The Record from Recorded Future News

Conducted a destructive intrusion against LACMTA involving data exfiltration and destruction of infrastructure, and was also linked to additional intrusions affecting organizations in Israel, Turkey, Saudi Arabia, and other sectors. The group is described as tied to Iran's MOIS while presenting itself as a standalone hacktivist crew.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping35

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables10

Domains, IPs, and hashes tied to this actor, refreshed continuously.