Skip to content
IsraelState-AlignedActive

Predatory Sparrow

Caused physical damage to a steel mill and published the CCTV footage. Operates under a hacktivist persona with capability no hacktivist has.

Download profile JSON
Active
2021–present
Motivation
Sabotage / Destruction, Information Operations
Aliases
5
Exploited CVEs
0
ATT&CK techniques
8
Cited sources
4

Overview

Predatory Sparrow — Gonjeshke Darande in Persian — conducts disruptive operations against Iranian infrastructure with a level of capability and operational restraint that is inconsistent with the hacktivist identity it claims.

Its June 2022 operation against Iranian steel producers is one of very few publicly documented cyberattacks to cause visible physical damage. The group released CCTV footage from inside the Khouzestan Steel Company showing a ladle of molten metal spilling and igniting a fire, and stated that it had timed the attack to avoid injuring workers — a claim consistent with the footage, which shows an evacuated area.

Its October 2021 attack on Iran's fuel distribution network disabled the subsidy card system used at filling stations nationwide, disrupting fuel purchases across the country and displaying a message on station displays. In December 2023 it disabled a reported majority of fuel stations in Iran again. In June 2025 it claimed responsibility for an attack on Bank Sepah and the destruction of approximately $90 million in cryptocurrency at the Iranian exchange Nobitex — funds that were provably burned rather than stolen, sent to addresses with no recoverable private key.

The group publishes its operations with polished branding, video evidence, and pointed messaging aimed at the Iranian public and government. Analysts broadly assess it as an Israeli state or state-directed operation using a hacktivist persona, though no government has confirmed this and no formal attribution exists.

Attribution

Down to the named unit where public evidence supports it.

Israel (assessed)Not publicly designatedLow confidence

No government has attributed Predatory Sparrow, and the group presents itself as an independent hacktivist collective. Industry and academic assessment widely holds that the operational sophistication, ICS-specific capability, target selection, intelligence requirements, and demonstrated restraint indicate a state or state-directed actor, with Israel the assessed sponsor. This assessment is inferential and should be treated as materially less certain than the indicted attributions elsewhere in this dataset.

Attributing sources

Cross-vendor naming crosswalk

5 designators across 5 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

Microsoft Threat Intelligence

index ↗
  • Predatory Sparrow

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Predatory Sparrow

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • Predatory Sparrow

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Dragos

index ↗
  • Not tracked as a named ICS grouppartialDemonstrated ICS capability but not assigned a Dragos mineral designator in public reporting

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

CISA / NSA / FBI

index ↗
  • Gonjeshke DarandeThe group's Persian self-designation

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Meteor / Stardust / Cometwiper

Wiper family used against Iranian Railways and government targets, with modular deployment and message display components.

Malpedia ↗
ICS manipulationutility

Direct manipulation of industrial processes at steel production facilities, producing physical damage.

Payment system disruptionutility

Targeted disabling of the national fuel subsidy card infrastructure at filling stations.

Shared, commodity & living-off-the-land

Provable burn addressesutility

Cryptocurrency sent to addresses with no recoverable private key — destruction rather than theft, demonstrating the operation was not financially motivated.

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

2 stages · 8 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Campaign timeline

  1. landmark

    Iranian Steel Mill Attack

    Physical damage to production equipment at Khouzestan Steel Company, with the group publishing CCTV footage showing a ladle of molten metal spilling and igniting a fire. One of very few publicly documented cyberattacks to cause visible physical destruction; the group stated it timed the attack to avoid injuring workers.

    ManufacturingCritical Infrastructure

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.