Mabna Institute
Mabna Institute is an Iranian Advanced Persistent Threat (APT) group active since 2013, focused on the theft of research data, intellectual property, and credentials from universities, government agencies, and private sector organizations. Primarily motivated by financial gain, the group has…
Nimbus Manticore
List of names used by industry: Date founded:The group is believed to have been active since June 2022. Affiliation:The group has been affiliated with the Islamic Revolutionary Guard Corps and overlaps with other Iranian hacking groups such as Crimson Sandstorm.Nimbus…
MuddyWater
List of names used by the industry: Date founded: MuddyWater was first publicly identified in 2017 and is known to use a wide range of tools and techniques in its operations. The name “MuddyWater” was coined by Palo Alto Networks…
Haghjoyan
List of names used by industry: Date founded: Affiliation: Social media handles/websites: Telegram: @Haghjoyann (Allegedly seized) Previous operations: The group’s first activity was to target and deface 50 websites, they provided a Hack-DB link to prove their activities. These attacks…
Behzad Mesri
Behzad Mesri is an Iran-based hacker and former CEO of the Net Peygard Samavat Company (later rebranded as Emennet Pasargad). He is publicly accused, by the US, of conducting high‑profile intrusions, data theft, extortion, and participating in state‑aligned malicious cyber…
Homeland Justice
Homeland Justice is a state-aligned Iranian hacktivist persona used by the Ministry of Intelligence and Security (MOIS) to conduct disruptive cyberattacks and psychological-operations campaigns, most notably against Albania since 2022. The group has carried out ransomware and wiper attacks, leaked…
Ababil of Minab
Ababil of Minab is a new pro-Iranian hacking group. The group named itself after the missile attack on Shajareh Tayyebeh School in Minab, Hormuzgan province in Southern Iran which occured on the 28 February 2026 resulting in the death of…
Ravin Academy
Ravin Academy is an Iranian cybersecurity training academy established in 2019 with the aim of improving Iran’s cybersecurity industry by providing advanced educational, research and cybersecurity services. It also functions as a sophisticated cyber-attack group, actively involved in espionage, sabotage…
Charming Kitten
Charming Kitten is an Iranian state-aligned cyber actor that seeks to target human rights activists, academic researchers, media outlets and individuals who are of interest to Iran’s government and security agencies. Unlike other Iranian APT groups focussed on disruptive cyber…
Helix Kitten
List of names used by the industry: Sub group: Lyceum (also known as HEXANE, Storm-0133, SiameseKitten) Date founded: Active since at least 2014. Affiliation: Iranian state-sponsored. Affiliated to Iran’s Ministry of Intelligence and Security (MOIS). Operations primarily to conduct cyber…







