🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
PREDATORY SPARROW

/actor/predatory-sparrow/  ·  0 intel reports

Year Established
2021
Attribution
Israel (Suspected)
Motivation
Sabotage, Geopolitical, Counter-Iran
Modus Operandi (MO)
Destructive ICS/SCADA attacks against Iranian infrastructure, wiper malware, psychological operations
Primary Aliases
Gonjeshke Darande (Persian translation)

Predatory Sparrow (known in Persian as Gonjeshke Darande, meaning "predatory sparrow") is a threat actor group widely suspected by security researchers to represent an Israeli state-sponsored or state-directed operation, based on the sophistication of its attacks, their exclusive targeting of Iranian critical infrastructure, and the geopolitical context of Israel-Iran cyber conflict. The group has never been officially attributed by any government, and operates in a grey zone between state-sponsored sabotage and plausibly deniable hacktivism.

Predatory Sparrow is responsible for some of the most consequential cyberattacks ever conducted against civilian infrastructure. In December 2021, they claimed responsibility for an attack on Iranian fuel distribution systems that disabled the electronic fuel subsidy card system used by Iranian citizens at thousands of petrol stations across the country , displaying a political message on station screens and causing hours-long queues and public frustration. The attack demonstrated both sophisticated ICS knowledge and a deliberate calibration of impact to maximise public pressure on the Iranian government without causing casualties.

In 2022, Predatory Sparrow attacked Khouzestan Steel Company and two other major Iranian steel manufacturers, deploying custom malware that caused a steel production line to fail catastrophically, with dramatic footage of a molten steel pour going out of control shared publicly by the group. Simultaneously, another cluster of attacks targeted Iranian railway infrastructure. These operations represent rare documented cases of state-sponsored cyberattacks causing confirmed physical damage.

The group's operational philosophy appears deliberately calibrated , maximising economic and psychological impact on the Iranian state and public while avoiding actions that would kill civilians, suggesting strategic restraint consistent with a state actor concerned about escalation thresholds and international legal norms governing cyber warfare.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Predatory Sparrow requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles