Individual threat actor

CYLAMI

CYLAMI is an Iranian actor-controlled Telegram media and offensive-tool project that combines pro-Iran and anti-Israel messaging with public development or promotion of automated SSH and RDP cracking, vulnerability scanning, proxy supply, card-checking, website compromise, DDoS and doxing.

CYLAMI presents a hybrid profile combining patriotic hacktivism, offensive-tool development, credential attacks and fraud enablement. Its public channel is unusually explicit about intended automation and user workflow.

The tool descriptions emphasize lowering technical barriers: automatic range acquisition, scanning, vulnerability checks, password attacks, proxy collection and bot-based reporting.

INFERENCE (confidence: high): CYLAMI seeks influence through capability distribution as much as through direct operations, positioning itself as an enablement node for less-skilled operators.

INFERENCE (confidence: medium-high): the card-checking and proxy-sales activity introduces direct financial-cybercrime incentives alongside political targeting.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-19

ATT&CK

MITRE ATT&CK

T1021.001Remote Desktop Protocol
T1021.004SSH
T1110.001Password Guessing
T1190Exploit Public-Facing Application
T1491.002External Defacement
T1498.001Direct Network Flood
T1585.001Social Media Accounts
T1587.004Exploits
T1595.001Scanning IP Blocks
T1595.002Vulnerability Scanning

Research

Selected OSINT