Initial Access
1 technique·derived
Valid Accounts.
Caused physical damage to a steel mill and published the CCTV footage. Operates under a hacktivist persona with capability no hacktivist has.
Predatory Sparrow — Gonjeshke Darande in Persian — conducts disruptive operations against Iranian infrastructure with a level of capability and operational restraint that is inconsistent with the hacktivist identity it claims.
Its June 2022 operation against Iranian steel producers is one of very few publicly documented cyberattacks to cause visible physical damage. The group released CCTV footage from inside the Khouzestan Steel Company showing a ladle of molten metal spilling and igniting a fire, and stated that it had timed the attack to avoid injuring workers — a claim consistent with the footage, which shows an evacuated area.
Its October 2021 attack on Iran's fuel distribution network disabled the subsidy card system used at filling stations nationwide, disrupting fuel purchases across the country and displaying a message on station displays. In December 2023 it disabled a reported majority of fuel stations in Iran again. In June 2025 it claimed responsibility for an attack on Bank Sepah and the destruction of approximately $90 million in cryptocurrency at the Iranian exchange Nobitex — funds that were provably burned rather than stolen, sent to addresses with no recoverable private key.
The group publishes its operations with polished branding, video evidence, and pointed messaging aimed at the Iranian public and government. Analysts broadly assess it as an Israeli state or state-directed operation using a hacktivist persona, though no government has confirmed this and no formal attribution exists.
Down to the named unit where public evidence supports it.
No government has attributed Predatory Sparrow, and the group presents itself as an independent hacktivist collective. Industry and academic assessment widely holds that the operational sophistication, ICS-specific capability, target selection, intelligence requirements, and demonstrated restraint indicate a state or state-directed actor, with Israel the assessed sponsor. This assessment is inferential and should be treated as materially less certain than the indicted attributions elsewhere in this dataset.
Attributing sources
5 designators across 5 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Wiper family used against Iranian Railways and government targets, with modular deployment and message display components.
Malpedia ↗Direct manipulation of industrial processes at steel production facilities, producing physical damage.
Targeted disabling of the national fuel subsidy card infrastructure at filling stations.
Shared, commodity & living-off-the-land
Cryptocurrency sent to addresses with no recoverable private key — destruction rather than theft, demonstrating the operation was not financially motivated.
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Valid Accounts.
7 techniques·derived
Meteor wiper deployment. ICS technique — direct manipulation of steel production processes. ICS technique — messaging displayed on fuel station terminals.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Physical damage to production equipment at Khouzestan Steel Company, with the group publishing CCTV footage showing a ladle of molten metal spilling and igniting a fire. One of very few publicly documented cyberattacks to cause visible physical destruction; the group stated it timed the attack to avoid injuring workers.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.