{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "predatory-sparrow",
    "slug": "predatory-sparrow",
    "name": "Predatory Sparrow",
    "shortName": "Predatory Sparrow",
    "country": "Israel",
    "countryCode": "IL",
    "sponsorship": "state-aligned",
    "status": "active",
    "activeSince": "2021",
    "prominence": 73,
    "tagline": "Caused physical damage to a steel mill and published the CCTV footage. Operates under a hacktivist persona with capability no hacktivist has.",
    "bio": "Predatory Sparrow — Gonjeshke Darande in Persian — conducts disruptive operations against Iranian infrastructure with a level of capability and operational restraint that is inconsistent with the hacktivist identity it claims.\n\nIts June 2022 operation against Iranian steel producers is one of very few publicly documented cyberattacks to cause visible physical damage. The group released CCTV footage from inside the Khouzestan Steel Company showing a ladle of molten metal spilling and igniting a fire, and stated that it had timed the attack to avoid injuring workers — a claim consistent with the footage, which shows an evacuated area.\n\nIts October 2021 attack on Iran's fuel distribution network disabled the subsidy card system used at filling stations nationwide, disrupting fuel purchases across the country and displaying a message on station displays. In December 2023 it disabled a reported majority of fuel stations in Iran again. In June 2025 it claimed responsibility for an attack on Bank Sepah and the destruction of approximately $90 million in cryptocurrency at the Iranian exchange Nobitex — funds that were provably burned rather than stolen, sent to addresses with no recoverable private key.\n\nThe group publishes its operations with polished branding, video evidence, and pointed messaging aimed at the Iranian public and government. Analysts broadly assess it as an Israeli state or state-directed operation using a hacktivist persona, though no government has confirmed this and no formal attribution exists.",
    "attribution": {
      "sponsor": "Israel (assessed)",
      "service": "Not publicly designated",
      "confidence": "low",
      "summary": "No government has attributed Predatory Sparrow, and the group presents itself as an independent hacktivist collective. Industry and academic assessment widely holds that the operational sophistication, ICS-specific capability, target selection, intelligence requirements, and demonstrated restraint indicate a state or state-directed actor, with Israel the assessed sponsor. This assessment is inferential and should be treated as materially less certain than the indicted attributions elsewhere in this dataset.",
      "sources": [
        {
          "org": "Check Point Research",
          "title": "Analysis of the Iranian fuel distribution system attack",
          "url": "https://research.checkpoint.com/",
          "date": "2021-11-01"
        },
        {
          "org": "CyberScoop",
          "title": "Predatory Sparrow's attacks on Iranian steel facilities and infrastructure",
          "url": "https://cyberscoop.com/",
          "date": "2022-06-28"
        }
      ]
    },
    "motivations": [
      "sabotage",
      "information-operations"
    ],
    "targetSectors": [
      "Manufacturing",
      "Critical Infrastructure",
      "ICS / SCADA",
      "Energy",
      "Financial Services",
      "Transportation",
      "Cryptocurrency",
      "Oil & Gas"
    ],
    "targetCountries": [
      "Iran"
    ],
    "aliases": [
      {
        "org": "microsoft",
        "name": "Predatory Sparrow",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "Predatory Sparrow",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Gonjeshke Darande",
        "correlation": "exact",
        "note": "The group's Persian self-designation"
      },
      {
        "org": "mandiant",
        "name": "Predatory Sparrow",
        "correlation": "exact"
      },
      {
        "org": "dragos",
        "name": "Not tracked as a named ICS group",
        "correlation": "partial",
        "note": "Demonstrated ICS capability but not assigned a Dragos mineral designator in public reporting"
      }
    ],
    "tools": [
      {
        "name": "Meteor / Stardust / Comet",
        "type": "wiper",
        "custom": true,
        "description": "Wiper family used against Iranian Railways and government targets, with modular deployment and message display components.",
        "malpediaSlug": "win.meteor"
      },
      {
        "name": "ICS manipulation",
        "type": "utility",
        "custom": true,
        "description": "Direct manipulation of industrial processes at steel production facilities, producing physical damage."
      },
      {
        "name": "Payment system disruption",
        "type": "utility",
        "custom": true,
        "description": "Targeted disabling of the national fuel subsidy card infrastructure at filling stations."
      },
      {
        "name": "Provable burn addresses",
        "type": "utility",
        "custom": false,
        "description": "Cryptocurrency sent to addresses with no recoverable private key — destruction rather than theft, demonstrating the operation was not financially motivated."
      }
    ],
    "techniques": [
      {
        "tCode": "T1485",
        "name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "tCode": "T1561.002",
        "name": "Disk Wipe: Disk Structure Wipe",
        "tactic": "Impact",
        "note": "Meteor wiper deployment"
      },
      {
        "tCode": "T0831",
        "name": "Manipulation of Control",
        "tactic": "Impact",
        "note": "ICS technique — direct manipulation of steel production processes"
      },
      {
        "tCode": "T0832",
        "name": "Manipulation of View",
        "tactic": "Impact",
        "note": "ICS technique — messaging displayed on fuel station terminals"
      },
      {
        "tCode": "T1491.002",
        "name": "Defacement: External Defacement",
        "tactic": "Impact"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact",
        "note": "Cryptocurrency destroyed rather than stolen"
      },
      {
        "tCode": "T1499",
        "name": "Endpoint Denial of Service",
        "tactic": "Impact"
      }
    ],
    "cves": [],
    "relationships": [
      {
        "relatedActorId": "cyberav3ngers",
        "type": "operational-overlap",
        "confidence": "low",
        "note": "Adversaries, not associates — opposing sides of the Iran–Israel exchange, both operating under hacktivist personas."
      }
    ],
    "reports": [
      {
        "org": "SentinelOne",
        "title": "Meteor Express: Mysterious Wiper Paralyzes Iranian Trains",
        "url": "https://www.sentinelone.com/labs/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll/",
        "date": "2021-07-29"
      },
      {
        "org": "Check Point Research",
        "title": "Analysis of Iranian fuel distribution disruption",
        "url": "https://research.checkpoint.com/",
        "date": "2021-11-01"
      }
    ],
    "campaigns": [
      {
        "id": "khouzestan-steel",
        "actorId": "predatory-sparrow",
        "name": "Iranian Steel Mill Attack",
        "date": "2022-06-27",
        "significance": "landmark",
        "targetSectors": [
          "Manufacturing",
          "Critical Infrastructure"
        ],
        "targetCountries": [
          "Iran"
        ],
        "cveIds": [],
        "summary": "Physical damage to production equipment at Khouzestan Steel Company, with the group publishing CCTV footage showing a ladle of molten metal spilling and igniting a fire. One of very few publicly documented cyberattacks to cause visible physical destruction; the group stated it timed the attack to avoid injuring workers.",
        "sources": [
          {
            "org": "CyberScoop",
            "title": "Predatory Sparrow's attacks on Iranian steel facilities",
            "url": "https://cyberscoop.com/",
            "date": "2022-06-28"
          }
        ]
      }
    ],
    "flag": "🇮🇱",
    "profile": "/apt/predatory-sparrow/"
  }
}