CSIDB logo
Threat actor

ASOR

Attribution profile

Type
Hacker
Location
Iran
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-30 22:08
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known publicly as ASOR, also referred to as the ASOR Hack Team. Open‑source reporting indicates that the group operates from Iran. These two elements—alias and geographic location—are the only details consistently cited in available sources. No further biographical or organizational information about the group has been disclosed in reputable cybersecurity publications. Consequently, any description of the actor's internal structure or leadership remains undocumented.

Publicly accessible reports do not specify which industries or sectors the ASOR Hack Team typically targets. Likewise, there is no disclosed information about the geographic regions that the group focuses on. Because no targeting patterns have been published, the actor's strategic objectives—whether financial gain, espionage, disruption, or other aims—cannot be inferred from reliable sources. Absent concrete evidence, any assertion about motive or goal would be speculative and is therefore omitted. The lack of targeting data also means that no known campaign objectives have been attributed to the group with confidence.

No malware families, exploit tools, or initial‑access vectors have been linked to ASOR in the technical analyses that are publicly available. Similarly, no specific tooling style or custom utilities have been described in relation to this actor. Attribution to a state sponsor, criminal consortium, or any other affiliation has not been established in open‑source threat intelligence. Consequently, no notable campaigns or publicly reported operations can be confidently ascribed to the ASOR Hack Team. Because no technical indicators have been released, defenders cannot produce specific detection rules for this group. Likewise, no public advisories have named ASOR as a responsible party in any incident. The absence of verifiable technical details prevents any assessment of the group's sophistication or resource level. Thus, the only confirmed facts about ASOR are its aliases and its presumed location in Iran. All other aspects of the actor's activity remain undocumented in the current body of public reporting. This profile reflects the limits of presently available information and will be updated should reliable details emerge.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB