Cyber Threat Actor: Hackers of Savior
| Actor Type | Location | Known Incidents |
Activist
|
Iran
|
3 incidents |
|---|
Characteristics
Profile
Hackers of Savior, also referenced as Hackers of Saviors, is a threat actor group that has been publicly linked to Iran and described in open sources as having ties to Palestinian causes. The group operates under the alias Hackers of Savior and has been identified in multiple incident reports as originating from or being supported by Iranian sources. These attributions are based on the descriptions provided in the cited articles, which label the actors as Iranian‑linked hackers and note their claimed association with Palestinian‑related motivations. No further details about the group’s size, structure, or internal hierarchy are available in the source material.
The actor’s known activity has been directed toward targets located in Israel, spanning both the financial and logistics sectors. In one incident the group asserted unauthorized access to the interbank transfer network used by Israeli banks, specifically naming Bank Leumi as the target of their claimed intrusion. In a separate episode the group claimed responsibility for an attack on a logistics and port terminal operator, stating they had gained deep network access and subsequently leaked security camera footage and internal system images. These actions demonstrate a pattern of targeting critical infrastructure and financial systems within the same geographic region, although the sources do not explicitly state the underlying strategic objectives such as financial gain, espionage, or disruption.
The publicly reported operations attributed to Hackers of Savior include the alleged compromise of Bank Leumi’s money‑transfer system in April 2022 and the disruption of a logistics and port terminal’s computer systems in January 2022. The articles describing these events do not reference specific malware families, initial access vectors, or particular tooling styles associated with the group, so no detailed TTP themes can be extracted from the provided information. Consequently, the profile is limited to the confirmed facts of the group’s aliases, alleged Iranian linkage, stated connection to Palestinian causes, the sectors and regions they have targeted, and the two representative campaigns outlined above. No additional speculative details are included.
