Predatory Sparrow (Gonjeshke Darande) is a disruptive, hacktivist-branded actor that conducts high-impact sabotage and wiper operations against Iranian critical infrastructure and financial systems, widely assessed to align with Israeli interests.
Predatory Sparrow surfaced publicly in 2021 and is unusual among MENA-relevant actors for prioritizing physical and financial disruption over quiet espionage. It presents as a hacktivist collective under the Persian name Gonjeshke Darande, but the scale, precision and destructive engineering of its operations lead most analysts to assess a state or state-linked actor aligned with Israel. It has no MITRE ATT&CK group ID.
Operationally the group couples network intrusion with destructive payloads and safety-system manipulation, then amplifies impact through media releases, leaked source code and provocative messaging, blending sabotage with information operations. Its target is consistently Iran: it claimed the 2021 disruption of Iran's fuel-distribution network and 2022 attacks that caused a fire at the Khouzestan steel plant (Predatory Sparrow released CCTV footage of the incident).
In June 2025, amid heightened Israel-Iran conflict, the group escalated financially: it wiped data at Bank Sepah (an institution it said finances the IRGC) and destroyed roughly $90 million on the Iranian crypto exchange Nobitex, sending funds to unspendable vanity addresses denouncing the IRGC and later leaking Nobitex's source code. The operation was analyzed by FDD, eSecurity Planet and the NATO CCDCOE cyber-law toolkit.
MENA relevance is defined by its exclusive focus on Iranian targets. Confidence in the activity is high (well-documented, self-claimed with corroboration); confidence in the Israel-alignment attribution is medium-to-high but remains an assessment.