CSIDB logo
Threat actor

Iran Cyber Security Group Hackers

Attribution profile

Type
Activist
Location
Iran
Known incidents
6 incidents
Sources
2 sources
First seen
2012-01-01
Last seen
2020-04-24
Updated
2026-07-31 06:11
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor described in the source material is referred to as an Iranian hacking group, with no specific alias provided in the reporting. Public attribution links this group to destructive cyber operations, including the wiping of hard drives and disruption of email services at a Las Vegas casino, which the source explicitly attributes to Iran. The group’s public statements indicate a protest motive against the Saudi‑led military campaign in Yemen, declaring that it will continue to target Saudi‑defense‑related sites until the conflict ends. This establishes a clear strategic objective of political disruption rather than financial gain, as the actor’s own messaging ties its actions to geopolitical grievances.

Targeting observed in the source includes Saudi defense‑related websites, which the actor claims to strike in response to the Yemen conflict, and the Las Vegas casino incident, where the actor’s tactics resulted in data destruction and service outages. Additional activity noted in the same reporting involves Saudi‑origin actors compromising Iranian state‑media social‑media accounts and the Iranian ministry of defense website, the Yemen Cyber Army compromising the Saudi Ministry of Foreign Affairs and leaking plain‑text login credentials, and the Syrian Electronic Army—described as pro‑Assad hackers—defacing the Washington Post’s mobile site. While these latter incidents involve different actors, they are presented in the source as part of the broader regional cyber‑conflict environment in which the Iranian group operates.

Observed tactics, techniques and procedures referenced in the material consist of destructive malware that wipes storage devices and disables email systems, website defacement or alteration, and the acquisition and disclosure of plain‑text credentials. No specific malware families, exploit kits, or intrusion vectors are mentioned in the source, so the description is limited to these observed effects. The actor’s operational style appears to focus on visible impact—service disruption and public messaging—rather than covert espionage or financial theft.

Attribution in the open‑source material points to Iranian hackers as the perpetrators of the Vegas casino wiper attack and the Saudi‑defense‑site protests, without explicitly stating a state‑sponsorship link; therefore, the profile notes only the public attribution to Iranian actors. No information is provided about the group’s size, organizational structure, financial motives, or broader geopolitical affiliations beyond the stated protest against the Saudi‑led Yemen campaign. The profile therefore remains confined to the facts presented: an Iranian‑linked hacking collective that has conducted disruptive website defacements, wiper attacks, and credential leaks in pursuit of political objectives related to the Yemen conflict.

Incidents

Attributed incidents are available to members.

6 incidents

Sources

Sources available to members: 2 sources.

CSIDB