Arvin Club
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Arvin Club is a cyber threat actor that operates under the alias Arvin Club and has been linked to Iran in open source reporting. The group maintains a presence on Telegram, running both an official channel with around three thousand subscribers and additional chat groups, and it operates an Onion website hosted on the TOR network to publish updates and leaked data. Their communications are primarily in Persian, and they promote a motto that translates to “Freedom to connect,” which appears in their public postings. Arvin Club describes itself as a ransomware‑oriented group but does not deploy encryption‑based ransomware or demand payment from victims.
The actor’s observed activity focuses on the education sector in India, specifically targeting central government school networks such as the Kendriya Vidyalaya chain. In the reported incidents they exfiltrated personally identifiable information of students and published the data on their Telegram channels and Onion site without attempting to encrypt files or extort the victim. Their tactics, techniques, and procedures emphasize data exfiltration and public disclosure rather than traditional ransomware payloads, and they rely on sophisticated hacking methods to gain access to target networks. No specific malware families, exploit kits, or initial access vectors are detailed in the sources; the group’s tooling style is characterized by the use of messaging platforms for coordination and a TOR hidden service for leak distribution.
Regarding attribution, Arvin Club has publicly denied any connection to the Iranian government despite allegations that surfaced in mid‑2021, and they have not been linked to any state‑sponsored campaign in the available material. The group has expressed support for the now‑disbanded REvil ransomware operation, notably posting a mocking meme after REvil members were arrested by the FBI, but no formal affiliation or consortium membership is documented. The most concrete campaign attributed to Arvin Club is the breach of Indian school systems that resulted in the exposure of student PII, which they publicized through their Telegram and Onion channels without claiming responsibility for every incident listed on their leak site. This pattern of leaking data without extortion defines their publicly reported operations to date.
Incidents
Attributed incidents are available to members.
2 incidents