Gonjeshke Darande — Persian for "Predatory Sparrow" — is a self-styled hacktivist persona that has, since 2021, conducted a sustained campaign of destructive cyberattacks against Iranian critical infrastructure and financial systems, consistently timed to align with Israeli-Iranian military and political flashpoints. The group presents itself publicly as a coalition of Iranian dissidents opposed to the Islamic Republic, but is widely assessed by journalists, researchers, and anonymous Western officials to be linked to, or directly operated by, the Israeli government or military — an attribution the Israeli government has never confirmed and the group itself has never claimed.
What distinguishes this group from typical hacktivist collectives is the operational sophistication and physical consequence of its attacks: it has used custom wiper malware to disable Iran's national railway system and state broadcaster, disrupted the nationwide subsidized-fuel payment network not once but at least twice (2021 and again in 2023, the latter affecting an estimated 70% of gas stations), and — in its most consequential operation — compromised industrial control systems at three of Iran's largest steel producers in June 2022, triggering a molten-metal spill and fire at Khouzestan Steel Company that the group itself filmed and published. That steel mill attack is widely regarded as the first publicly documented cyber operation to cause visible physical damage to heavy industrial equipment since Stuxnet in 2010.
The group escalated further during the June 2025 "Twelve-Day War" between Israel and Iran, claiming responsibility for disrupting Iran's state-owned Bank Sepah (which it accused of financing the IRGC and Iran's missile programs) and, the following day, for compromising Nobitex, Iran's largest cryptocurrency exchange — stealing an estimated $90 million in crypto assets and then deliberately "burning" the funds by transferring them to addresses with no known private keys, rendering the money permanently unspendable rather than keeping it for financial gain. The group also published Nobitex's source code and internal infrastructure documentation.
Gonjeshke Darande has cultivated an unusual reputation for what some researchers term "ethical" or restrained destructive hacking: in the steel mill attack it claims to have timed the sabotage to occur after workers had cleared the area, and it frames its operations publicly as retaliation for specific regime actions rather than indiscriminate harm. Whether genuine restraint or calculated reputation management for a state-linked influence operation, this positioning — combined with a conspicuous silence since a joint US-Israel military campaign against Iran began in February 2026 — makes the group's true nature, chain of command, and current operational status among the most closely watched open questions in state-aligned cyber operations today.
LOW-MEDIUM on the specific question of Israeli state sponsorship, despite widespread journalistic and analytical consensus that this is the most likely explanation. The operational sophistication required to reach production-control systems at multiple industrial sites, the precise timing of operations with Israeli military and political developments, and anonymous statements from US defense officials naming Israel as responsible for at least the 2021 fuel-system attack all point toward state involvement. However, no government has ever officially confirmed a relationship, the group itself has never claimed state affiliation, and — as with many "hacktivist front" operations — the persona's design may be specifically intended to preserve plausible deniability indefinitely.
This group's operations show a consistent pattern of gaining deep, often administrator-level access to victim networks well before executing a visible, deliberately public act of disruption — behavior more consistent with a well-resourced, patient intrusion than opportunistic hacktivism. Initial access methods have not been fully disclosed publicly for most operations, but the consistent presence of custom-built wiper malware (the Meteor family) tailored to specific Iranian government and industrial targets indicates dedicated malware-development resources and pre-operation reconnaissance, rather than off-the-shelf tooling.
Once inside IT environments, the group has favored destructive rather than covert techniques: the Meteor wiper overwrites files with zero-bytes, deletes Windows Event Viewer logs and shadow copies, disables or evades installed antivirus, changes local passwords, and modifies desktop wallpapers and lock screens to display its own messaging directly to victims and the public — treating compromised systems as a broadcast channel for psychological and political messaging rather than simply disabling them quietly.
The group's most consequential escalation came in 2022, when its intrusion reached beyond conventional IT systems into the production-control (OT/ICS) environment at Khouzestan Steel Company, manipulating an overhead crane's control system to discharge molten metal onto the factory floor — demonstrating the ability to translate a cyber intrusion into a physical, kinetic-equivalent industrial accident. In its 2025 financial-sector operations, the group again showed willingness to go beyond disruption into deliberate, irreversible destruction: rather than monetizing the $90 million stolen from Nobitex, it transferred the funds to blockchain addresses with no known private keys, permanently destroying the value rather than keeping it — a symbolic statement that the operation was punitive rather than financially motivated.
| Type | Value / Description | Source | Date |
|---|---|---|---|
| MALWARE | Meteor wiper (MITRE Software S0688) | MITRE ATT&CK; Check Point Research | 2021-07 |
| MALWARE | Stardust / Comet wipers (Indra lineage, possible tooling ancestor) | Check Point Research | 2019–2021 |
| EVENT | Khouzestan Steel Company HMI screenshot and CCTV footage (self-published proof) | Predatory Sparrow Telegram channel; CyberScoop | 2022-06-27/28 |
| FINANCIAL | ~$90M in Nobitex crypto assets transferred to unrecoverable ("burn") blockchain addresses | Elliptic (via NBC News, CNBC) | 2025-06-18 |
| NOTE | No durable static IP/domain/hash indicator list is included here. This actor conducts infrequent, highly bespoke operations against a single country's infrastructure, self-publishes its own "proof" via Telegram/X rather than leaving conventional forensic trails in open reporting, and no consolidated public IOC feed exists. Consult MITRE ATT&CK Software S0688 (Meteor) and named vendor incident reports (Check Point, and other Iran-focused researchers) for the limited technical indicators that have been published. | ||
This group occupies a distinctive position in the threat landscape: it is one of the very few publicly documented actors to have caused verified physical damage to industrial equipment through a cyber intrusion, placing it in the same rare category as Stuxnet in terms of demonstrated cyber-to-physical impact, but achieved with what appears to be a far smaller, more agile operation than the multi-year, multi-agency Stuxnet effort. This suggests either a highly capable, well-funded state cyber unit operating under a hacktivist cover identity, or a smaller but unusually skilled team with direct access to ICS engineering expertise — both possibilities carry serious implications for how OT-focused critical infrastructure operators everywhere assess their own exposure to similarly resourced, similarly motivated adversaries.
The group's consistent operational restraint — publicly claiming to time attacks to avoid civilian casualties, and destroying rather than keeping stolen cryptocurrency — is either genuine ethical calculation unusual among destructive threat actors, or a deliberate reputation-management strategy consistent with a state actor seeking to normalize destructive cyber operations as an acceptable tool of statecraft by demonstrating "responsible" use. Both interpretations should concern defenders: the first because it suggests a capable actor deliberately holding back further escalation that remains available to it, and the second because it suggests a state normalizing destructive cyberattacks against civilian-adjacent infrastructure as a legitimate policy tool.
The group's apparent silence since June 2025, spanning a major escalation in US-Israel military action against Iran beginning in February 2026, is the most significant open question in this profile. If it is genuinely dormant, that would mark an unexplained break from six years of consistent activity aligned precisely with this kind of escalation. If it remains active but unreported — plausible given wartime restrictions on Iranian internet access and information flow — then organizations tracking this actor should not interpret the current quiet period as evidence of reduced capability or intent. Confidence in either direction would improve significantly with corroborated reporting once full information about the 2026 conflict period becomes available.