CYLAMI
CYLAMI is an Iranian actor-controlled Telegram media and offensive-tool project that combines pro-Iran and anti-Israel messaging with public development or promotion of automated SSH and RDP cracking, vulnerability scanning, proxy supply, card-checking, website compromise, DDoS and doxing.
CYLAMI presents a hybrid profile combining patriotic hacktivism, offensive-tool development, credential attacks and fraud enablement. Its public channel is unusually explicit about intended automation and user workflow.
The tool descriptions emphasize lowering technical barriers: automatic range acquisition, scanning, vulnerability checks, password attacks, proxy collection and bot-based reporting.
INFERENCE (confidence: high): CYLAMI seeks influence through capability distribution as much as through direct operations, positioning itself as an enablement node for less-skilled operators.
INFERENCE (confidence: medium-high): the card-checking and proxy-sales activity introduces direct financial-cybercrime incentives alongside political targeting.
ATT&CK
MITRE ATT&CK
Research