CSIDB logo
Threat actor

Gonjeshke Darande

Attribution profile

Type
Activist
Location
Israel
Known incidents
9 incidents
Sources
3 sources
First seen
2022-06-27
Last seen
2025-06-18
Updated
2026-08-01 04:17
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Predatory Sparrow, also known as Gonjeshk’e Darandeh or Gonjeshke Darande, is a threat actor that has publicly claimed responsibility for a series of cyber operations targeting Iranian entities. Open‑source reporting identifies the group as being linked to Israel, with Iranian officials frequently accusing it of having ties to the Israeli state. The actor’s aliases appear in multiple incident reports and are used interchangeably in statements claiming responsibility for attacks against Iranian critical infrastructure, financial institutions and commercial services.

The actor’s stated motivations, as expressed in its own claims, are primarily political and retaliatory. It has described attacks on an Iranian cryptocurrency exchange as a political statement against the Iranian regime, framed the disruption of Bank Sepah as retaliation for the bank’s alleged financing of Iran’s military and nuclear programs, and characterized strikes on Iranian ports and petrol stations as responses to alleged Iranian aggression or to earlier attempted cyber operations against Israeli water infrastructure. These statements indicate a strategic focus on disruption and signaling rather than financial gain, although the 2025 cryptocurrency exchange intrusion resulted in the theft of approximately $81.7 million in digital assets, demonstrating a capacity for financially motivated outcomes when the opportunity arises.

Observed tactics, techniques and procedures across the reported incidents include exploiting weak access controls to drain hot‑wallet funds in a cryptocurrency exchange, destroying or disrupting banking infrastructure to impede customer services, compromising operational technology environments to halt steel production and trigger physical effects such as equipment malfunction, and targeting fuel‑distribution networks to force petrol stations into manual operation. The actor has also breached closed‑circuit television systems to monitor and validate the physical impact of its intrusions, exfiltrated video footage, and leveraged known operational‑technology weaknesses such as insufficient network segmentation, outdated systems and lack of intrusion‑detection capabilities to move laterally within victim networks. Past claims reference earlier operations against Iranian railways and steel factories that resulted in explosions caused by cyber means, indicating a pattern of targeting industrial control systems to cause tangible disruption. While the group asserts a pro‑Israel motive and Iran attributes the activity to Israeli state actors, the available sources do not provide definitive evidence of formal state sponsorship, and no further details about the actor’s size, internal structure or financial motivations are disclosed in the supplied material.

Incidents

Attributed incidents are available to members.

9 incidents

Sources

Sources available to members: 3 sources.

CSIDB