Cyber Threat Actor: Iran Cyber Security Group Hackers
| Actor Type | Location | Known Incidents |
Activist
|
Iran
|
6 incidents |
|---|
Profile
The threat actor is known by several aliases, including Iran Cyber Security Group Hackers, Iranian Cyber Security Group, and Iran Hack Security Team. Open‑source reporting associates the group with Iran, though the exact location within the country is not specified in the available sources. The aliases appear in claim messages left after website defacements and in statements attributed to the hackers. The actor has been observed conducting operations that range from symbolic web alterations to attempts at disrupting critical services.
Targeting has focused on governmental and critical infrastructure entities in the Middle East and on foreign interests perceived as adversarial. Incidents include an attempted disruption of Israeli water utilities during a COVID‑19 outbreak, a defacement of a U.S. government library website, and a compromise of Bahraini electricity and water authority systems. The actor has also struck Saudi defense sites and used a compromised Swedish military server to launch a distributed denial‑of‑service attack against major U.S. financial institutions. Observed objectives therefore involve causing operational disruption, delivering political or protest messages, and demonstrating capability against adversarial infrastructure.
The actor’s tactics, as described in the sources, rely heavily on exploiting exposed web applications to gain initial access and then altering site content. In the Swedish military server case, a security flaw was exploited to hijack the system and use it as a foothold for a large‑scale DDoS campaign. No specific malware families are mentioned in the reporting; the emphasis is on web defacement, server hijacking, and leveraging compromised infrastructure for traffic amplification. Tooling style appears to be opportunistic, using whatever vulnerable assets are available rather than deploying custom malware suites.
Attribution assessments vary by incident. U.S. and foreign intelligence officials have linked the water‑utility attempt and the Bahraini infrastructure disruption to Iranian actors, while the library defacement was deemed likely the work of Iranian sympathizers without confirmed state sponsorship. The Royal Saudi Air Force intrusion was explicitly claimed by an individual identifying with the Iran Hack Security Team and framed as a protest against Saudi actions in Yemen. Representative operations cited in the open‑source record include the attempted Israeli water‑utility disruption, the U.S. library defacement, the Swedish‑server‑enabled DDoS against U.S. banks, and the Saudi Air Force website protest.
