◇ SIGN IN
← all actors
apt

Predatory Sparrow

activemedium confidence
APT / State-sponsored
Gonjeshke DarandeIndra (suspected overlap)
Attribution
Hacktivist-branded group widely assessed to align with Israeli interests; likely state or state-linked, attribution unconfirmed
Origin
Unknown (Israel-aligned, assessed)
First seen
2021
Last active
2025
Motivation
Sabotage / Information operations
Confidence
medium
MENA targeting
Iran
Sectors
Rail transport, steel manufacturing, fuel distribution, banking
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Iran (Rail transport, steel manufacturing, fuel distribution sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Predatory Sparrow (Gonjeshke Darande) is a disruptive, hacktivist-branded actor that conducts high-impact sabotage and wiper operations against Iranian critical infrastructure and financial systems, widely assessed to align with Israeli interests.

History

Predatory Sparrow surfaced publicly in 2021 and is unusual among MENA-relevant actors for prioritizing physical and financial disruption over quiet espionage. It presents as a hacktivist collective under the Persian name Gonjeshke Darande, but the scale, precision and destructive engineering of its operations lead most analysts to assess a state or state-linked actor aligned with Israel. It has no MITRE ATT&CK group ID.

Operationally the group couples network intrusion with destructive payloads and safety-system manipulation, then amplifies impact through media releases, leaked source code and provocative messaging, blending sabotage with information operations. Its target is consistently Iran: it claimed the 2021 disruption of Iran's fuel-distribution network and 2022 attacks that caused a fire at the Khouzestan steel plant (Predatory Sparrow released CCTV footage of the incident).

In June 2025, amid heightened Israel-Iran conflict, the group escalated financially: it wiped data at Bank Sepah (an institution it said finances the IRGC) and destroyed roughly $90 million on the Iranian crypto exchange Nobitex, sending funds to unspendable vanity addresses denouncing the IRGC and later leaking Nobitex's source code. The operation was analyzed by FDD, eSecurity Planet and the NATO CCDCOE cyber-law toolkit.

MENA relevance is defined by its exclusive focus on Iranian targets. Confidence in the activity is high (well-documented, self-claimed with corroboration); confidence in the Israel-alignment attribution is medium-to-high but remains an assessment.

Notable campaigns

2021
Iran fuel-system disruption
Claimed a cyberattack that disabled Iran's nationwide fuel-distribution/subsidy card system, causing widespread outages.
2022
Khouzestan steel plant sabotage
Caused a fire at an Iranian steel facility and released CCTV footage, demonstrating destructive OT-level impact.
2025
Bank Sepah and Nobitex operation
Wiped data at IRGC-linked Bank Sepah and destroyed ~$90M on the Nobitex crypto exchange, then leaked its source code.