Home/Threat Actor/Predatory Sparrow
Threat Actor

Predatory Sparrow

predatory_sparrow · israel_aligned_suspected_military_intelligence · active since 2021-07

Predatory Sparrow / Gonjeshke Darande (canonical English + Persian naming, the latter meaning "Predatory Sparrow" in Farsi) is a pro-Israel hacktivist collective widely believed to be linked to Israeli Military Intelligence Directorate conducting sustained anti-Iran counter-state cyber operations since 2021.

Israeli Military Intelligence Directorate suspected attribution via Times of Israel canonical ("The group is believed to be linked to the Israeli Military Intelligence Directorate") + The Record / Recorded Future News ("widely believed to be linked to Israeli military intelligence") + Axios ("Predatory Sparrow, an Israeli hacking group") + CNBC + Time Magazine + Bitdefender + Wikipedia + former NSA cyber director Rob Joyce commentary ("Predatory Sparrow's past cyber attacks on Iranian steel plants and gas stations have demonstrated tangible effects in Iran") + Radware Tel Aviv state-linked groups report.

Israeli government has not officially acknowledged conducting offensive cyber operations; standalone cluster paralleling cyber_partisans + it_army_ukraine + ghostsec in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

operational target profile Iranian state-owned critical infrastructure including fuel distribution + rail transit + steel industry + banking + cryptocurrency exchanges + Khuzestan Steel Co. + Bank Sepah (U.S. Treasury sanctioned 2007 + 2018 for IRGC missile program support) + Nobitex cryptocurrency exchange, with signature cluster-defining selective-targeting tradecraft avoiding emergency services and partial gas-station sparing.

operational attack architecture: (1) cluster-defining kinetic-effect ICS cyber capability demonstrated June 2022 Khuzestan Steel Co. attack with severe fire + machine suddenly spewing molten steel, sophisticated industrial control system attack producing physical damage and production halt.

(2) cluster-defining critical infrastructure mass-disruption December 18, 2023 Iran gas station attack disrupting 70% of pumps with payment systems + central server + station management compromise + cluster-defining "Khamenei, playing with fire has a price" signature messaging tradecraft ("We, Gonjeshke Darande, carried out another cyberattack today, taking out a majority of the gas pumps throughout Iran. This cyberattack comes in response to the aggression of the Islamic Republic and its proxies in the region")

(3) cluster-defining 2021 Iranian fuel distribution cyberattack + 2021 Iranian rail transit system attack first public emergence establishing operational pattern.

(4) cluster- defining June 17 2025 Bank Sepah cyberattack with data destruction during Israel-Iran military escalation ("This is what happens to institutions dedicated to maintaining the dictator's terrorist fantasies") + parallel Nobitex cryptocurrency exchange attack.

(5) cluster-defining "controlled manner" + emergency services advance warning + selective-sparing signature operational tradecraft ("As in our previous operations, this cyberattack was conducted in a controlled manner while taking measures to limit potential damage to emergency services. We delivered warnings to emergency services across the country before the operation began, and ensured a portion of the gas stations across the country were left unharmed for the same reason, despite our access and capability to completely disrupt their operation") distinguishing Predatory Sparrow from typical hacktivist operations and indicating sophisticated mission planning consistent with state-linked operations.

(6) signature Persian self-identification influence- operation tradecraft ("Gonjeshke Darande" = "Predatory Sparrow" Farsi naming portraying selves as Iranian anti-government hacktivists despite widely-acknowledged Israeli intelligence linkage); (7) Telegram + X/Twitter bilingual Persian/English operational announcement channels.

cluster fills the 2021-2025-Israel-aligned-anti-Iran + Iranian- fuel-rail-steel-banking-cryptocurrency-targeting + Khuzestan-steel-mill-kinetic-effect + Bank-Sepah- Nobitex-2025-Israel-Iran-military-escalation + "controlled-manner"-sophisticated-tradecraft + Persian-self-identification position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

canonical illustration of Israel- suspected counter-state cyber operations + kinetic- effect ICS cyber capability + critical infrastructure mass-disruption + banking-system data destruction + sophisticated selective-targeting tradecraft + Persian self-identification influence operation cited in essentially all subsequent Israel-Iran cyber-confrontation industry analyses through 2021-2026 period.

israel_aligned_suspected_military_intelligence confidence: high 14 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Predatory Sparrow / Gonjeshke Darande (canonical English + Persian naming) is a pro-Israel hacktivist collective widely believed to be linked to Israeli Military Intelligence Directorate (per Times of Israel + The Record + Axios + Israeli media) conducting sustained anti-Iran cyber operations since 2021. Israeli Military Intelligence Directorate suspected attribution via multiple major-media sources + former NSA cyber director Rob Joyce commentary + Radware Tel Aviv state-linked groups report. The Israeli government has not officially acknowledged conducting offensive cyber operations.

Standalone cluster paralleling cyber_partisans + it_army_ukraine + ghostsec in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

Operational target profile
  • Iranian state-owned critical infrastructure: fuel distribution + rail + steel + banking + cryptocurrency.
  • Iranian critical industrial facilities: Khuzestan Steel Co.
  • Iranian financial sector: Bank Sepah + Nobitex.
  • Selectively avoids emergency services via signature tradecraft Operational attack architecture: (1) Kinetic-effect ICS cyber capability (cluster- defining): Khuzestan steel mill June 2022 with severe fire + molten steel spewing, sophisticated ICS/PLC attack producing physical damage (2) Critical infrastructure mass-disruption (cluster-defining): December 2023 70% Iran gas station disruption with payment systems + central server + station management compromise (3) Banking system data destruction (cluster- defining): June 2025 Bank Sepah cyberattack with data deletion during Israel-Iran military escalation (4) Cryptocurrency exchange attack (cluster- defining): June 2025 Nobitex during military escalation (5) "Controlled manner" selective-targeting signature tradecraft (cluster-defining): emergency services advance warning + gas station partial-sparing (6) Persian self-identification influence operation (signature): "Gonjeshke Darande" Farsi naming portraying selves as Iranian anti-government hacktivists (7) "Khamenei, playing with fire has a price" signature messaging tradecraft: distinctive operational announcement pattern The cluster fills the 2021-2025-Israel-aligned- anti-Iran + Iranian-fuel-rail-steel-banking- cryptocurrency-targeting + Khuzestan-steel-mill- kinetic-effect + Bank-Sepah-Nobitex-2025-Israel- Iran-military-escalation + "controlled-manner"- sophisticated-tradecraft + Persian-self- identification position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

Aliases

14
predatory_sparrowpredatory sparrowgonjeshke_darandegonjeshke darandeگنجشک درندهpredatory sparrow pro-israel hacktivist grouppredatory sparrow israeli military intelligence directorate suspectedpredatory sparrow 2021 iranian fuel cyberattackpredatory sparrow july 2021 iranian rail transit attackpredatory sparrow june 2022 iranian khuzestan steel mill molten steel firepredatory sparrow december 2023 iran gas station 70 percent disruptedpredatory sparrow june 2025 bank sepah nobitex cryptocurrency exchangepredatory sparrow controlled cyberattack measures limit potential damage emergency servicespredatory sparrow khamenei playing with fire has a price

Notable Campaigns

9
2025Predatory Sparrow June 17 2025 Bank Sepah Cyberattack During Israel-Iran Military Escalation
2025Predatory Sparrow Nobitex Cryptocurrency Exchange Attack (2025)
2023Predatory Sparrow December 2023 Iran Gas Station 70% Disruption Cyberattack
2022Predatory Sparrow Iranian Khuzestan Steel Mill Attack, Kinetic-Effect Signature (June 2022)
2021-2026Continued Industry Reference Status (2021-2026)
2021-2025Predatory Sparrow 'Controlled Manner' + Emergency Services Warning Signature Tradecraft
2021-2025Predatory Sparrow Persian Self-Identification Signature Tradecraft
2021Predatory Sparrow Iranian Rail Transit System Attack, First Public Emergence (July 2021)
2021Predatory Sparrow 2021 Iranian Fuel Distribution Cyberattack (October 2021)

Attribution & Reporting

Attributed by
Wikipedia (canonical longstanding tracking + 2021-2025 attribution timeline)Times of Israel (canonical December 2023 gas station + Khuzestan steel mill Israeli Military Intelligence Directorate attribution)The Record / Recorded Future News (canonical June 2025 Bank Sepah Israeli military intelligence link attribution + Radware Tel Aviv report citation)Axios (canonical June 17, 2025 Bank Sepah pro-Israel hackers cyberattack attribution + Rob Joyce former NSA cyber director commentary)CNBC (canonical December 2023 Iran gas station 70% disruption coverage with Israel-linked attribution)Bitdefender / HotForSecurity (canonical December 2023 gas station coverage + nation-state sponsorship assessment)Time Magazine (canonical December 18 2023 Iran gas station cyberattack coverage)INKL (canonical Israeli broadsheet implications coverage)Rob Joyce (former NSA cyber director canonical commentary)Radware Tel Aviv (canonical Israeli state-linked groups report cited by The Record)The Register (canonical sophistication + nation-state-sponsorship assessment cited by Bitdefender)
Key reporting
reportWikipedia: Predatory Sparrow, canonical longstanding 2021-2025 tracking
reportTimes of Israel: Israel-linked group claims cyberattack that shut down 70% of Iran's gas stations (December 2023), canonical Israeli Military Intelligence Directorate attribution
reportThe Record / Recorded Future News: Pro-Israel hackers claim breach of Iranian bank amid military escalation (June 2025)
reportAxios: Pro-Israel hackers take credit for cyberattack on Iran's Bank Sepah (June 17, 2025)
reportCNBC: Predatory Sparrow (Gonjeshke Darande) claim cyberattack on Iran's gas stations (December 2023)
reportTime Magazine: What to Know About the Cyber Attack on Iran's Gas Stations (December 2023)
reportBitdefender HotForSecurity: Hacktivists Claim Responsibility for Disrupting Iran's Gas Stations (December 2023)
reportRob Joyce former NSA cyber director: canonical commentary on tangible-effects-in-Iran assessment
reportRadware Tel Aviv: canonical Israeli state-linked groups report (cited by The Record)

Operational

State sponsor

Israeli Military Intelligence Directorate, widely believed linkage per Times of Israel + The Record / Recorded Future News + Axios + Israeli media coverage. Israeli government has not officially acknowledged conducting offensive cyber operations against Iran. Predatory Sparrow publicly portrays self as Iranian anti-government hacktivists despite widely-accepted Israeli intelligence linkage. Per The Record: "Although Israel does not officially acknowledge conducting offensive cyber operations, multiple high-impact cyber incidents targeting Iran's fuel infrastructure, railways and industrial facilities have been attributed to Israeli state- linked groups, Tel Aviv-based cybersecurity firm Radware said in a report last week." Attribution chain: (1) Wikipedia canonical longstanding tracking: per Wikipedia: "Predatory Sparrow (Persian: گنجشک درنده, romanized: Gonjeshke Darande) is a pro-Israel hacker group with possible links to the Israeli government. Since 2021, the group has claimed responsibility for multiple cyberattacks targeting Iran, including the 2021 Iranian fuel cyberattack, attacks on several Iranian steel mills in 2022, and attacks on Bank Sepah and the Nobitex cryptocurrency exchange in 2025. Predatory Sparrow publicly emerged in 2021 with a series of attacks on Iranian transit systems. They portray themselves as a group of Iranian anti-government hacktivists, often using their Farsi name. However, Predatory Sparrow is widely believed, including by Israeli media, to be linked to the Israeli government or military. The Israeli government has not confirmed any ties with the group." (2) Times of Israel canonical December 2023 gas station attribution: per Times of Israel: "The group is believed to be linked to the Israeli Military Intelligence Directorate. It claimed responsibility for a cyberattack last year that forced the Iranian state-owned Khuzestan Steel Co. to halt production." (3) The Record / Recorded Future News canonical June 2025 Bank Sepah attribution: per The Record: "Predatory Sparrow, also known by its Persian name, Gonjeshke Darande, is widely believed to be linked to Israeli military intelligence. The group has previously claimed responsibility for high-profile cyberattacks targeting Iran's state-owned steel company, gas stations, and fuel distribution systems." (4) Axios + Rob Joyce canonical Bank Sepah analysis June 2025: per Axios: "Predatory Sparrow, an Israeli hacking group, said today that it is behind a series of cyberattacks against Iran's Bank Sepah. The group, which publicly goes by the Farsi translation of its name, Gonjeshke Darande, added that it's also deleted the state- owned banking system's data." Per Rob Joyce (former NSA cyber director): "Predatory Sparrow's past cyber attacks on Iranian steel plants and gas stations have demonstrated tangible effects in Iran. Disrupting the availability of this bank's funds, or triggering a broader collapse of trust in Iranian banks, could have major impacts there." (5) Bitdefender canonical state-sponsorship assessment: per Bitdefender via The Register: "experts believe the group is either 'operated, or sponsored, by a nation state' due to their sophistication and high impact." (6) CNBC canonical December 2023 gas station coverage: per CNBC: "A hacking group widely reported as being linked to Israel has taken responsibility for a cyberattack that's knocked out the majority of gas stations across Iran, leading to long lines of cars and angry crowds." Operational mission objective: Counter-state cyber operations against Iranian regime targeting critical national infrastructure + state-owned industrial + financial entities in apparent coordinated geopolitical messaging against Iranian government policy + Iranian proxy forces ("This cyberattack comes in response to the aggression of the Islamic Republic and its proxies in the region"). Demonstrates kinetic- effect cyber capability (Khuzestan steel mill molten-steel fire incident.

70% gas station disruption.

banking sector disruption during military escalation).

Operational target profile
  • Iranian state-owned critical infrastructure , fuel distribution + rail + steel + banking.
  • Iranian critical industrial facilities, Khuzestan Steel Co.
  • Iranian financial sector, Bank Sepah (U.S. Treasury-sanctioned 2007 for IRGC missile program support)
  • Iranian cryptocurrency exchanges, Nobitex June 2025.
  • Selectively avoid emergency services per operational tradecraft signature The cluster fills the 2021-2025-Israel-aligned- anti-Iran + Iranian-fuel-rail-steel-banking- cryptocurrency-targeting + "controlled-manner"- sophisticated-tradecraft + Khuzestan-steel-mill- kinetic-effect + Bank-Sepah-Nobitex-2025-Israel- Iran-military-escalation position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
Motivations
israel_aligned_anti_iran_counter_state_cyber_operations, iranian_state_critical_infrastructure_disruption_objective, iranian_regime_pressure_messaging_objective, iranian_proxy_force_geopolitical_response_objective, kinetic_effect_cyber_capability_demonstration_signature, controlled_manner_selective_targeting_emergency_services_avoidance_signature_tradecraft
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)49/60 · 81%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)18/60 · 30%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin