CSIDB logo
Threat actor

Attackers from three countries including Saudi Arabia

Attribution profile

Type
Activist
Location
Saudi Arabia
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 01:42
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is described in open sources as a group of hackers operating from three Arab countries, with leadership attributed to individuals based in Saudi Arabia. No specific alias or moniker is provided in the reporting, and the actor is referenced only by the geographic origin of its members. The location of the core elements of the group is indicated as Saudi Arabia, according to the statements made by Iranian officials following the incident.

The actor’s known activity involves targeting a Iranian government entity, specifically the Statistical Centre of Iran, which experienced a temporary outage on 24 May 2016. The sector affected is public administration, and the geographic focus of the operation is Iran. Iranian officials characterized the objective as disruption of service and a show‑of‑force effort, explicitly stating that no sensitive or classified information was compromised and that the attack remained at the first layer of the system.

Regarding tactics, techniques and procedures, the reporting mentions that the attack was conducted from three countries and led by hackers in Saudi Arabia, employing what was described as “deceive attacks.” The nature of these techniques is not detailed further, and no malware families, specific initial access vectors, or particular tooling styles are disclosed in the available material. Consequently, the only observable TTP theme is the use of a multi‑origin, low‑impact disruption aimed at causing temporary service interruption.

Attribution claims come exclusively from Iranian authorities, who asserted that the hackers originated in Saudi Arabia and shared IP address information with that country via Interpol; no independent verification or additional evidence of state sponsorship or criminal consortium affiliation is presented in the source. The most notable publicly reported operation linked to this actor is the May 2016 breach of Iran’s Statistical Centre, which resulted in a brief denial‑of‑service effect and was dismissed by Iranian officials as a non‑technical, demonstrative action. No further campaigns or operations are described in the provided information.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB