GhyamSarnegouni
Attribution profile
- Type
- Activist
- Location
- Iran
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2023-05-29
- Last seen
- 2023-05-29
- Updated
- 2026-08-01 07:20
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
GhyamSarnegouni, also known as Rise to Overthrow, is a dissident hacking group that first appeared on Telegram in January 2022 and is based in Iran. The group’s public messaging frequently references the Mojahedin‑e Khalq (MEK) opposition movement, indicating a perceived ideological affinity rather than a formal state sponsorship. Its aliases are used interchangeably in statements and on social media channels where it posts claimed exploits.
The actor’s observed targets are limited to Iranian governmental institutions, specifically the offices of the president and the foreign ministry, both located within Iran. Its stated purpose is to protest the regime by exposing internal operations, which it describes as embarrassing rather than critically damaging, and to disrupt online presences through website defacement. No financial gain is mentioned in the source material; the objectives appear to be reputational harm and the dissemination of sensitive information as a form of political dissent.
Regarding tactics, techniques and procedures, the referenced articles do not specify particular malware families, phishing methods, or initial access vectors. Instead, the group claims to have seized control of approximately 120 servers and more than 1,300 computers connected to the president’s internal network, accessed security footage, obtained classified internal communications, and exfiltrated diplomatic correspondence, network topologies and floor plans. Website defacement is noted, with the insertion of images of MEK leaders Massoud Rajavi and Maryam Rajavi on the compromised pages.
Notable operations attributed to GhyamSarnegouni include the May 2023 breach of the Iranian presidential offices that resulted in the leak of sensitive documents and the simultaneous defacement of associated sites. Earlier in the same month the group asserted responsibility for hacking Iranian foreign ministry servers and defacing related websites, again accompanied by the posting of MEK‑linked imagery. These incidents represent the primary publicly reported campaigns through which the group has demonstrated its capability to infiltrate and disrupt Iranian government infrastructure.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.