Predatory Sparrow
Predatory Sparrow / Gonjeshke Darande (canonical English + Persian naming, the latter meaning "Predatory Sparrow" in Farsi) is a pro-Israel hacktivist collective widely believed to be linked to Israeli Military Intelligence Directorate conducting sustained anti-Iran counter-state cyber operations since 2021.
Israeli Military Intelligence Directorate suspected attribution via Times of Israel canonical ("The group is believed to be linked to the Israeli Military Intelligence Directorate") + The Record / Recorded Future News ("widely believed to be linked to Israeli military intelligence") + Axios ("Predatory Sparrow, an Israeli hacking group") + CNBC + Time Magazine + Bitdefender + Wikipedia + former NSA cyber director Rob Joyce commentary ("Predatory Sparrow's past cyber attacks on Iranian steel plants and gas stations have demonstrated tangible effects in Iran") + Radware Tel Aviv state-linked groups report.
Israeli government has not officially acknowledged conducting offensive cyber operations; standalone cluster paralleling cyber_partisans + it_army_ukraine + ghostsec in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
operational target profile Iranian state-owned critical infrastructure including fuel distribution + rail transit + steel industry + banking + cryptocurrency exchanges + Khuzestan Steel Co. + Bank Sepah (U.S. Treasury sanctioned 2007 + 2018 for IRGC missile program support) + Nobitex cryptocurrency exchange, with signature cluster-defining selective-targeting tradecraft avoiding emergency services and partial gas-station sparing.
operational attack architecture: (1) cluster-defining kinetic-effect ICS cyber capability demonstrated June 2022 Khuzestan Steel Co. attack with severe fire + machine suddenly spewing molten steel, sophisticated industrial control system attack producing physical damage and production halt.
(2) cluster-defining critical infrastructure mass-disruption December 18, 2023 Iran gas station attack disrupting 70% of pumps with payment systems + central server + station management compromise + cluster-defining "Khamenei, playing with fire has a price" signature messaging tradecraft ("We, Gonjeshke Darande, carried out another cyberattack today, taking out a majority of the gas pumps throughout Iran. This cyberattack comes in response to the aggression of the Islamic Republic and its proxies in the region")
(3) cluster-defining 2021 Iranian fuel distribution cyberattack + 2021 Iranian rail transit system attack first public emergence establishing operational pattern.
(4) cluster- defining June 17 2025 Bank Sepah cyberattack with data destruction during Israel-Iran military escalation ("This is what happens to institutions dedicated to maintaining the dictator's terrorist fantasies") + parallel Nobitex cryptocurrency exchange attack.
(5) cluster-defining "controlled manner" + emergency services advance warning + selective-sparing signature operational tradecraft ("As in our previous operations, this cyberattack was conducted in a controlled manner while taking measures to limit potential damage to emergency services. We delivered warnings to emergency services across the country before the operation began, and ensured a portion of the gas stations across the country were left unharmed for the same reason, despite our access and capability to completely disrupt their operation") distinguishing Predatory Sparrow from typical hacktivist operations and indicating sophisticated mission planning consistent with state-linked operations.
(6) signature Persian self-identification influence- operation tradecraft ("Gonjeshke Darande" = "Predatory Sparrow" Farsi naming portraying selves as Iranian anti-government hacktivists despite widely-acknowledged Israeli intelligence linkage); (7) Telegram + X/Twitter bilingual Persian/English operational announcement channels.
cluster fills the 2021-2025-Israel-aligned-anti-Iran + Iranian- fuel-rail-steel-banking-cryptocurrency-targeting + Khuzestan-steel-mill-kinetic-effect + Bank-Sepah- Nobitex-2025-Israel-Iran-military-escalation + "controlled-manner"-sophisticated-tradecraft + Persian-self-identification position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
canonical illustration of Israel- suspected counter-state cyber operations + kinetic- effect ICS cyber capability + critical infrastructure mass-disruption + banking-system data destruction + sophisticated selective-targeting tradecraft + Persian self-identification influence operation cited in essentially all subsequent Israel-Iran cyber-confrontation industry analyses through 2021-2026 period.