Homeland Cheetahs
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Homeland Cheetahs are a threat actor that has used the alias Homeland Cheetahs and is associated with Israel in the provided context. The group first came to public attention when it sent an email claiming responsibility for an explosion at Iran’s Natanz nuclear facility on 30 June 2020, stating that it consisted of dissidents inside Iran’s military and security forces. In the message the group included a propaganda video describing attacks on strategic sites inside Iran and asserted that it had carried out numerous earlier operations that Iranian authorities had concealed from the public. The email’s timing and the detailed video suggest pre‑knowledge of the incident, supporting the claim of an insider sabotage effort while also leaving open the possibility of a false‑flag operation by foreign actors.
The Homeland Cheetahs have been linked to a series of incidents targeting Iran’s strategic and economic infrastructure. According to reporting, the group’s actions are part of a broader pattern of mysterious fires and explosions that have struck nuclear sites, oil refineries, power plants, major factories and businesses across Iran since mid‑June 2020. Specific events cited include a blast at a liquid‑fuel production facility for ballistic missiles in Khojir on 26 June, an explosion at a medical clinic in Tehran on 30 June that killed 19 people, the Natanz blast on 2 July, a large fire in Shiraz on 3 July and an explosion and fire at a power plant in Ahwaz on 4 July. A journalist based in Finland, Saeed Aganji, has said that targeting these strategic and economic sites appears deliberate, with the aim of undermining Iran’s economy and pressuring the regime to cease financing militia groups. The actor’s activities have coincided with heightened cyber tensions, including an alleged Israeli prevention of a major cyber attack on Israel’s water system and a subsequent cyber attack on Iran’s Shahid Rajaae port that disrupted water canals and flooded roads.
In terms of tactics, the Homeland Cheetahs have relied on email communications to claim responsibility, accompanied by professionally produced propaganda videos that required considerable planning time. The group’s operations have involved physical sabotage such as explosives and fires, as evidenced by satellite imagery confirming fire damage at Natanz consistent with the group’s claims. Additionally, the actor has been associated with cyber‑oriented actions, namely the alleged cyber attack on Israel’s water infrastructure and the cyber disruption of Shahid Rajaae port, although the exact malware families or tools used are not detailed in the source material. Attribution remains uncertain; while unnamed intelligence officials have suggested Israeli involvement in the Natanz blast and Israeli officials have offered oblique remarks, no definitive public evidence confirms a state nexus or criminal consortium affiliation for the Homeland Cheetahs. The actor’s profile therefore rests on the claimed responsibility for specific incidents, the described targeting of Iranian strategic and economic sectors, and the observed use of email‑based propaganda combined with physical sabotage and alleged cyber operations.
Incidents
Attributed incidents are available to members.
1 incident