TLP:CLEAR
⚠ SUSPECTED NATION-STATE-ALIGNED (ISRAEL, UNCONFIRMED) · SELF-STYLED HACKTIVIST FRONT
// Threat Actor Profile — Destructive ICS & Financial-System Sabotage Against Iranian Infrastructure

GONJESHKE DARANDE

PROFILE COMPILED: 2026-08-29  |  SOURCES: MITRE ATT&CK (Software S0688 "Meteor"), Check Point Research, CyberScoop, NATO CCDCOE Cyber Law Toolkit, CNN, NBC News, TechCrunch, Picus Security, CloudSEK, Pylos, 8+ additional vendor/press sources
Status: LAST CONFIRMED ACTIVE JUN 2025 — SILENT THROUGH FEB 2026 ESCALATION
Threat Level: CRITICAL (Iran-Focused)
Primary Motive: Political/Military Retaliation & Signaling Against Iran
Active Since: 2021 (possible tooling lineage to 2019)
MITRE ATT&CK: No dedicated Group ID
⚡ THREAT UPDATE — 2026
Unusual silence during Feb 2026 US-Israel-Iran war breaks the group's established pattern
Despite a six-year history of striking Iranian infrastructure in close coordination with military and political escalation (the 2021 railway attack, 2022 Khouzestan Steel sabotage, and June 2025 Bank Sepah/Nobitex operations during the "Twelve-Day War"), the group has been conspicuously silent since a joint US-Israel military campaign against Iran began in February 2026, per open-source monitoring (CloudSEK; Pylos, May 2026). Analysts have not reached consensus on why — possibilities range from operational security amid tightened Iranian internet controls, to a shift toward purely kinetic/military coordination that no longer requires a public hacktivist persona, to simple wartime reporting gaps. This unexplained pattern break is itself a notable intelligence gap, not evidence the group has ceased to exist or lost capability.
2021
First Major Public Claim — Iranian Railway System (Meteor Wiper)
3
Largest Iranian Steel Producers Compromised in a Single 2022 Operation
$90M
Cryptocurrency Stolen and Permanently "Burned" in the 2025 Nobitex Attack
70%
Of Iran's Gas Stations Disrupted in the Dec 2023 Fuel-System Attack
00
Overview

Gonjeshke Darande — Persian for "Predatory Sparrow" — is a self-styled hacktivist persona that has, since 2021, conducted a sustained campaign of destructive cyberattacks against Iranian critical infrastructure and financial systems, consistently timed to align with Israeli-Iranian military and political flashpoints. The group presents itself publicly as a coalition of Iranian dissidents opposed to the Islamic Republic, but is widely assessed by journalists, researchers, and anonymous Western officials to be linked to, or directly operated by, the Israeli government or military — an attribution the Israeli government has never confirmed and the group itself has never claimed.

What distinguishes this group from typical hacktivist collectives is the operational sophistication and physical consequence of its attacks: it has used custom wiper malware to disable Iran's national railway system and state broadcaster, disrupted the nationwide subsidized-fuel payment network not once but at least twice (2021 and again in 2023, the latter affecting an estimated 70% of gas stations), and — in its most consequential operation — compromised industrial control systems at three of Iran's largest steel producers in June 2022, triggering a molten-metal spill and fire at Khouzestan Steel Company that the group itself filmed and published. That steel mill attack is widely regarded as the first publicly documented cyber operation to cause visible physical damage to heavy industrial equipment since Stuxnet in 2010.

The group escalated further during the June 2025 "Twelve-Day War" between Israel and Iran, claiming responsibility for disrupting Iran's state-owned Bank Sepah (which it accused of financing the IRGC and Iran's missile programs) and, the following day, for compromising Nobitex, Iran's largest cryptocurrency exchange — stealing an estimated $90 million in crypto assets and then deliberately "burning" the funds by transferring them to addresses with no known private keys, rendering the money permanently unspendable rather than keeping it for financial gain. The group also published Nobitex's source code and internal infrastructure documentation.

Gonjeshke Darande has cultivated an unusual reputation for what some researchers term "ethical" or restrained destructive hacking: in the steel mill attack it claims to have timed the sabotage to occur after workers had cleared the area, and it frames its operations publicly as retaliation for specific regime actions rather than indiscriminate harm. Whether genuine restraint or calculated reputation management for a state-linked influence operation, this positioning — combined with a conspicuous silence since a joint US-Israel military campaign against Iran began in February 2026 — makes the group's true nature, chain of command, and current operational status among the most closely watched open questions in state-aligned cyber operations today.

01
Identity & Attribution
Primary NameGonjeshke Darande ("Predatory Sparrow")
Sponsor / ParentUnconfirmed — widely suspected ties to the Israeli government or military (possibly an intelligence/cyber unit operating under a deniable hacktivist persona); Israel has never officially confirmed a relationship
Actor TypeSuspected Nation-State-Aligned / Self-Styled Hacktivist — Destructive ICS & Financial-System Sabotage
Primary MotivationPolitical/military signaling and retaliation against the Iranian government, IRGC, and entities assessed to fund Iranian military/proxy activity; psychological and symbolic impact appears deliberate alongside physical/financial disruption
Active SinceAt least 2021 (first major public claim); possible tooling lineage traces to the "Indra" persona active against Syrian targets since 2019
Last ObservedJune 2025 (Bank Sepah / Nobitex operations during the Israel-Iran "Twelve-Day War"); no confirmed public activity since — notably quiet through the Feb 2026 US-Israel military campaign against Iran
MITRE G-IDNot currently tracked under a dedicated Group ID; associated wiper (Meteor, S0688) is catalogued under the related "Indra" persona
Legal StatusNo indictments, sanctions, or formal legal action publicly disclosed against this persona or any named individual
Tracking Aliases
Gonjeshke Darande Predatory Sparrow
Attribution Confidence

LOW-MEDIUM on the specific question of Israeli state sponsorship, despite widespread journalistic and analytical consensus that this is the most likely explanation. The operational sophistication required to reach production-control systems at multiple industrial sites, the precise timing of operations with Israeli military and political developments, and anonymous statements from US defense officials naming Israel as responsible for at least the 2021 fuel-system attack all point toward state involvement. However, no government has ever officially confirmed a relationship, the group itself has never claimed state affiliation, and — as with many "hacktivist front" operations — the persona's design may be specifically intended to preserve plausible deniability indefinitely.

02
Campaign & Operational Timeline
2019
Possible Predecessor Activity — "Indra" Against Syria
A group calling itself Indra deploys early wiper tools ("Stardust," "Comet") against Syrian private companies from at least 2019; researchers later identify strong tooling similarities between Indra's malware and the "Meteor" wiper used in this group's first major Iran operation, suggesting possible shared origin without conclusive proof.
JUL 2021
Iranian Railway System Attack
Publicly claims responsibility for deploying the Meteor wiper against Iranian Railways and the Ministry of Roads and Urban Development, disabling train-scheduling systems and displaying taunting messages on station departure boards directing frustrated passengers to call the office of Iran's Supreme Leader.
OCT 2021
National Fuel-Card Payment System Attack
Disrupts Iran's nationwide subsidized-fuel smart-card payment network, stranding drivers at gas stations and displaying messages referencing the Supreme Leader's office on pump-station screens; Iranian officials publicly acknowledge the disruption as a cyberattack.
JAN 2022
Iranian State Broadcaster (IRIB) Hack
Claims an attack disrupting state-run TV and radio channels; Check Point researchers find wiper malware and tooling similarities to the Indra/Meteor lineage but cannot technically confirm this group's direct involvement.
JUN 2022
Khouzestan Steel Company Sabotage
Compromises industrial control systems at three of Iran's largest steel producers, triggering a molten-metal spill and fire at Khouzestan Steel that it films and publishes; widely cited as the first cyberattack to cause visible physical damage to heavy industrial equipment since Stuxnet.
DEC 2023
Second National Fuel-System Disruption
Claims responsibility for disabling an estimated 70% of Iran's gas station payment terminals nationwide, again disrupting the subsidized-fuel distribution system; Iran's oil minister publicly confirms a cyberattack as the cause.
JUN 2025
Bank Sepah & Nobitex Operations During the Twelve-Day War
Amid direct Israeli-Iranian military conflict, claims to have disrupted and erased data at state-owned Bank Sepah, then the next day claims responsibility for breaching Nobitex (Iran's largest crypto exchange), stealing and permanently "burning" an estimated $90 million in digital assets and publishing the exchange's source code and infrastructure documentation. Most recent publicly confirmed activity as of this writing.
03
Attack Lifecycle From IT wiping to OT physical sabotage — escalating impact across six years

This group's operations show a consistent pattern of gaining deep, often administrator-level access to victim networks well before executing a visible, deliberately public act of disruption — behavior more consistent with a well-resourced, patient intrusion than opportunistic hacktivism. Initial access methods have not been fully disclosed publicly for most operations, but the consistent presence of custom-built wiper malware (the Meteor family) tailored to specific Iranian government and industrial targets indicates dedicated malware-development resources and pre-operation reconnaissance, rather than off-the-shelf tooling.

Once inside IT environments, the group has favored destructive rather than covert techniques: the Meteor wiper overwrites files with zero-bytes, deletes Windows Event Viewer logs and shadow copies, disables or evades installed antivirus, changes local passwords, and modifies desktop wallpapers and lock screens to display its own messaging directly to victims and the public — treating compromised systems as a broadcast channel for psychological and political messaging rather than simply disabling them quietly.

The group's most consequential escalation came in 2022, when its intrusion reached beyond conventional IT systems into the production-control (OT/ICS) environment at Khouzestan Steel Company, manipulating an overhead crane's control system to discharge molten metal onto the factory floor — demonstrating the ability to translate a cyber intrusion into a physical, kinetic-equivalent industrial accident. In its 2025 financial-sector operations, the group again showed willingness to go beyond disruption into deliberate, irreversible destruction: rather than monetizing the $90 million stolen from Nobitex, it transferred the funds to blockchain addresses with no known private keys, permanently destroying the value rather than keeping it — a symbolic statement that the operation was punitive rather than financially motivated.

04
TTPs — MITRE ATT&CK Mapping Enterprise + ATT&CK for ICS; mapped from Meteor (S0688) and public incident reporting
Resource Development
T1587.001
Develop Capabilities: Malware
[HIGH] Developed and iterated custom wiper malware (Meteor and the related Stardust/Comet lineage) purpose-built for specific Iranian government, transport, and broadcast targets.
Reconnaissance
T1590
Gather Victim Network Information
[MEDIUM] Demonstrated detailed pre-operation knowledge of target network and, in the steel mill case, production-control system layout, consistent with extended reconnaissance before the visible attack.
Execution
T1059.001
Command and Scripting Interpreter: PowerShell
[HIGH] Meteor wiper executed via PowerShell and batch scripts to disable network adapters, change passwords, and orchestrate destructive routines.
Lateral Movement
T1484.001
Domain or Tenant Policy Modification: Group Policy Modification
[HIGH] Modified Group Policy Objects to distribute destructive scheduled tasks across networked machines, then removed compromised systems from the Active Directory domain post-attack.
Defense Evasion
T1562.001
Impair Defenses: Disable or Modify Tools
[HIGH] Disabled or removed licensing for installed antivirus (Kaspersky) and added malicious files to Windows Defender exclusion lists.
Defense Evasion
T1070.001
Indicator Removal: Clear Windows Event Logs
[HIGH] Deleted Security, System, and Application Event Viewer logs to hinder post-incident forensic investigation.
Impact
T1485
Data Destruction
[HIGH] Overwrote victim files with zero-bytes before deletion via the Meteor wiper across railway, broadcast, and other IT targets.
Impact
T1490
Inhibit System Recovery
[HIGH] Deleted boot configuration data and volume shadow copies (bcdedit, vssadmin) to prevent recovery of wiped systems.
Impact
T1491.002
Defacement: External Defacement
[HIGH] Modified desktop wallpapers, lock screens, and public-facing station/pump displays to broadcast political messaging directly to victims.
ATT&CK FOR ICS
Impair Process Control
T0831
Manipulation of Control
[HIGH] Manipulated production-control systems (HMI-visible) at Khouzestan Steel to trigger an unsafe overhead-crane discharge of molten metal.
ATT&CK FOR ICS
Impact
T0879
Damage to Property
[HIGH] Caused direct physical damage to industrial equipment and a factory fire as a deliberate outcome of the ICS intrusion, extending cyber impact into the physical domain.
Impact
T1657
Financial Theft
[MEDIUM] Stole an estimated $90 million in cryptocurrency from Nobitex, then deliberately rendered the funds permanently unrecoverable rather than retaining them for financial gain.
05
Targeting Profile
Sector Targeting
Government / Transportation (Rail, Ministries)
PRIMARY
Energy / Fuel Distribution
HIGH
Heavy Industry / Steel & Manufacturing (ICS/OT)
HIGH
Banking & Financial Services
MED
State Media / Broadcasting
MED
GeographiesExclusively Iran — every confirmed or claimed operation has targeted Iranian government, industrial, financial, or media entities; no operations against any other country have been publicly attributed to this persona
Victim ProfileIranian state-owned or state-affiliated organizations with high symbolic or strategic value — national rail and fuel-distribution networks, the state broadcaster, major industrial employers, and financial institutions specifically accused of funding the IRGC or Iran's missile/proxy programs
Preferred EntryNot fully disclosed publicly; consistent evidence of deep, extended-duration access preceding each attack suggests deliberate, well-resourced intrusion campaigns rather than opportunistic compromise
Target DoctrineOperations consistently timed to Israeli-Iranian political and military flashpoints and explicitly framed as retaliatory and proportionate; targets chosen for maximum symbolic/psychological visibility to the Iranian public and government rather than financial gain or intelligence collection
06
Tools, Malware & Infrastructure
Meteor Custom Wiper · MITRE S0688
Purpose-built Windows wiper that overwrites files with zero-bytes, deletes boot configuration data and shadow copies, disables antivirus, clears event logs, changes local account passwords, and modifies desktop wallpaper/lock screens to display attacker messaging; masquerades as a "Windows Power Efficiency Diagnostics" tool. Used in the 2021 Iranian railway and Ministry of Roads attack; technically linked to the earlier "Stardust" and "Comet" wiper lineage attributed to the "Indra" persona.
ICS/HMI Access Capability Bespoke ICS Intrusion Tooling · Uncatalogued
Capability sufficient to reach and manipulate production-control systems and an overhead crane's control logic at Khouzestan Steel Company; specific malware or access tooling for this operation has not been publicly recovered or catalogued, but the demonstrated outcome (deliberate unsafe equipment operation) implies OT-specific engineering knowledge well beyond typical IT-focused wiper deployment.
Custom Defacement / Messaging Payloads Public-Facing Display Manipulation
Software components used to alter public-facing displays — railway departure boards, fuel-pump payment terminals, desktop lock screens — to broadcast the group's political messaging directly to Iranian civilians, functioning as much as a psychological-operations tool as a destructive one.
Blockchain "Burn Wallet" Technique Financial Destruction Methodology
Rather than conventional cryptocurrency laundering, the group transferred an estimated $90 million stolen from Nobitex to blockchain addresses generated without corresponding private keys, permanently and verifiably destroying the funds — a technique that prioritizes demonstrable, irreversible punishment over financial gain.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 10 are NOT defanged.
Type Value / Description Source Date
MALWAREMeteor wiper (MITRE Software S0688)MITRE ATT&CK; Check Point Research2021-07
MALWAREStardust / Comet wipers (Indra lineage, possible tooling ancestor)Check Point Research2019–2021
EVENTKhouzestan Steel Company HMI screenshot and CCTV footage (self-published proof)Predatory Sparrow Telegram channel; CyberScoop2022-06-27/28
FINANCIAL~$90M in Nobitex crypto assets transferred to unrecoverable ("burn") blockchain addressesElliptic (via NBC News, CNBC)2025-06-18
NOTENo durable static IP/domain/hash indicator list is included here. This actor conducts infrequent, highly bespoke operations against a single country's infrastructure, self-publishes its own "proof" via Telegram/X rather than leaving conventional forensic trails in open reporting, and no consolidated public IOC feed exists. Consult MITRE ATT&CK Software S0688 (Meteor) and named vendor incident reports (Check Point, and other Iran-focused researchers) for the limited technical indicators that have been published.
08
Analyst Assessment
Overall Threat LevelCRITICAL (Iranian critical infrastructure specifically); not a global/enterprise threat given exclusively Iran-focused targeting
Attribution ConfidenceLOW-MEDIUM (state sponsorship) / HIGH (operations are genuine, sophisticated, and politically motivated)
TrajectoryUncertain — escalated steadily from IT wiping (2021) to OT physical sabotage (2022) to financial destruction (2025), but no confirmed activity since June 2025 despite a major Feb 2026 US-Israel campaign against Iran fitting its historical pattern
Most Dangerous CapabilityDemonstrated ability to translate cyber access into physical industrial damage (Khouzestan Steel) — one of a small number of publicly confirmed cyber-to-physical sabotage events in history alongside Stuxnet
Primary Intel GapDefinitive confirmation (or refutation) of Israeli state sponsorship, and the reason for the group's silence since June 2025 despite ongoing/escalating Israel-Iran conflict through 2026
Ecosystem / Affiliated Groups
Indra (possible predecessor / tooling lineage) CyberAv3ngers (comparable Iran-aligned counterpart, opposing side) Unit 8200 (speculated, unconfirmed connection)

This group occupies a distinctive position in the threat landscape: it is one of the very few publicly documented actors to have caused verified physical damage to industrial equipment through a cyber intrusion, placing it in the same rare category as Stuxnet in terms of demonstrated cyber-to-physical impact, but achieved with what appears to be a far smaller, more agile operation than the multi-year, multi-agency Stuxnet effort. This suggests either a highly capable, well-funded state cyber unit operating under a hacktivist cover identity, or a smaller but unusually skilled team with direct access to ICS engineering expertise — both possibilities carry serious implications for how OT-focused critical infrastructure operators everywhere assess their own exposure to similarly resourced, similarly motivated adversaries.

The group's consistent operational restraint — publicly claiming to time attacks to avoid civilian casualties, and destroying rather than keeping stolen cryptocurrency — is either genuine ethical calculation unusual among destructive threat actors, or a deliberate reputation-management strategy consistent with a state actor seeking to normalize destructive cyber operations as an acceptable tool of statecraft by demonstrating "responsible" use. Both interpretations should concern defenders: the first because it suggests a capable actor deliberately holding back further escalation that remains available to it, and the second because it suggests a state normalizing destructive cyberattacks against civilian-adjacent infrastructure as a legitimate policy tool.

The group's apparent silence since June 2025, spanning a major escalation in US-Israel military action against Iran beginning in February 2026, is the most significant open question in this profile. If it is genuinely dormant, that would mark an unexplained break from six years of consistent activity aligned precisely with this kind of escalation. If it remains active but unreported — plausible given wartime restrictions on Iranian internet access and information flow — then organizations tracking this actor should not interpret the current quiet period as evidence of reduced capability or intent. Confidence in either direction would improve significantly with corroborated reporting once full information about the 2026 conflict period becomes available.

09
Defensive Recommendations
01
Segment OT/ICS networks from IT networks and the internet. Ensure production-control systems (HMIs, PLCs, SCADA) have no direct or trivially bridgeable path from corporate IT networks, closing the pivot path this actor used to reach Khouzestan Steel's crane controls.
Counters: ICS T0831
02
Enforce safety interlocks independent of the control network. Deploy hardwired or logically isolated safety-instrumented systems that cannot be overridden purely through HMI/PLC-level access, so a network intrusion alone cannot trigger an unsafe physical action.
Counters: ICS T0831, T0879
03
Harden against wiper-style destructive malware. Maintain offline, immutable backups of critical system state and Active Directory; monitor for mass bcdedit/vssadmin execution, bulk file-overwrite activity, and unauthorized Group Policy changes distributing scheduled tasks.
Counters: T1485, T1490, T1484.001
04
Protect and centralize security logging off-host. Forward Event Viewer (Security/System/Application) logs to a separate, access-controlled SIEM immediately, since on-host log deletion — a core Meteor capability — only works if logs remain solely on the compromised host.
Counters: T1070.001
05
Monitor for antivirus/EDR tampering. Alert on AV license changes, service disablement, and additions to Windows Defender exclusion lists, which preceded destructive payload execution in documented Meteor deployments.
Counters: T1562.001
06
Restrict and monitor public-facing display/kiosk systems. Treat payment-terminal, departure-board, and other public-facing display systems as high-value targets in their own right, and isolate their update/content-management pathways from general IT networks.
Counters: T1491.002
07
Apply enhanced monitoring and cold-storage practices to high-value crypto holdings. Exchanges and custodians in politically exposed jurisdictions should assume destructive (not just theft-motivated) intrusions are possible, and architect hot-wallet exposure and withdrawal-approval workflows accordingly.
Counters: T1657
08
Assume politically timed targeting. Critical-infrastructure operators in geopolitically contested states should increase monitoring posture and incident-response readiness around known escalation windows (military strikes, diplomatic crises), matching this actor's demonstrated pattern.
Counters: General targeting-doctrine posture
10
References URLs are NOT defanged — navigate directly
Wikipedia
Accessed: 2026-08-29
MITRE ATT&CK
Accessed: 2026-08-29
Check Point Research
Accessed: 2026-08-29
Wikipedia
Accessed: 2026-08-29
Binding Hook
Accessed: 2026-08-29
Pylos
Accessed: 2026-08-29