Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationoperational-disruptiongovernment-diplomatic-threat

Hacktivist Campaigns Surge Amid US-Iran-Israel Tensions

Updated 12d agoFirst seen May 25, 202610 sources

Hacktivist activity has increased as tensions involving the United States, Iran, and Israel intensify, according to Sophos threat research. The reported campaigns indicate a rise in politically motivated cyber operations tied to the regional conflict, with threat actors using disruptive and influence-focused tactics to target organizations and amplify geopolitical messaging.

The activity reflects a broader pattern in which international crises quickly spill into cyberspace, raising the risk of website defacements, distributed denial-of-service attacks, and other opportunistic intrusions against public- and private-sector targets. Sophos said the escalation underscores the need for organizations with exposure to the region or to politically sensitive sectors to monitor for hacktivist threats and strengthen defensive readiness.

Share:
Hacktivist Campaigns Surge Amid US-Iran-Israel Tensions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 25, 202629d ago

Secureworks links Abraham's Ax to Moses Staff

Secureworks published research assessing that the threat activity tracked as Abraham's Ax was likely connected to the Moses Staff group. This introduced a specific attribution development separate from broader reporting on rising hacktivist activity tied to regional tensions.

Abraham's Ax Likely Linked to Moses Staff | SOPHOS
Apr 16, 20262mo ago

DarkOwl assesses Ashab al-Yamin as part of Iranian-aligned Telegram network

DarkOwl published analysis concluding that Harakat Ashab al-Yamin al-Islamia, which surfaced in early 2026 claiming attacks in Europe, is better understood as a front identity or media node within a broader Iranian-aligned Telegram ecosystem rather than a clearly distinct organization. The report cited fragmented channels, reposting overlap, and shared propaganda artifacts as indicators of coordinated amplification across affiliated networks.

Harakat Ashab al-Yamin al-Islamia: New Group or Broader Network
Mar 3, 20264mo ago

Sophos reports rise in hacktivist campaigns tied to U.S.-Iran-Israel tensions

Sophos published research stating that hacktivist activity had increased as conflict involving the United States, Iran, and Israel intensified. The reference does not provide specific underlying incident dates, so the publication date is used as the event date.

Feb 28, 20264mo ago

Cyber operations accompany U.S.-Israeli strikes on Iran

On February 28, cyber operations reportedly accompanied coordinated U.S.-Israeli airstrikes on Iran. Reported effects included compromise of the BadeSaba religious calendar app, defacements of Iranian news sites, attacks on government and military services, and major disruption to Iranian communications during a near-total internet blackout.

How Will Cyber Warfare Shape the U.S.-Israel Conflict with Iran?
Jun 24, 20251y ago

Hacktivists launch DDoS attacks on U.S. targets after Iran bombings

Cyble reported that hacktivist groups launched distributed denial-of-service attacks against U.S. targets following bombings involving Iran. This reflects a specific campaign development tied to regional geopolitical escalation, distinct from later attribution and trend reporting.

Hacktivists Launch DDoS Attacks At U.S. Following Iran Bombings
Aug 21, 20242y ago

X bans Handala hacking group's account

X suspended the account of the pro-Palestinian hacking group Handala as U.S. officials publicly criticized Iran over cyberattacks. The action marked an earlier platform and policy response tied to the broader cyber activity later associated with regional tensions.

‘Pro-Palestine’ hacking group banned on X as US criticizes Iran over cyberattacks | The Record from Recorded Future News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.