Hacktivist group

Cyber Fattah Team

Cyber Fattah Team (a.k.a. Cyber Fattah, sometimes branded as the “Islamic Resistance Cyber Team (Cyber Fattah team)”) is a pro-Iranian, ideologically motivated hacktivist / state-aligned actor active at least through 2025. The group self-identifies as an “Iranian cyber team” and operates primarily via Telegram (channels observed include @[redacted] and variants such as @[redacted]).

Open sources and vendor reporting consistently describe Cyber Fattah as:

Part of an Iran-aligned “Islamic Cyber Resistance” / “Holy League” constellation,

Conducting hack-and-leak, defacement, and disruption operations against Israeli, Gulf, Western, and now Saudi and U.S. targets, and

Using high-visibility incidents (e.g., Saudi Games 2024 data breach, Bank of Jerusalem breach) for propaganda and psychological operations rather than pure financial gain.

The group’s tradecraft centers on:

Exploiting web application vulnerabilities (including phpMyAdmin misconfigurations / SQLi) to gain backend access,

Deploying custom web shells / defacement scripts (e.g., a tool referred to as Def.php),

Exfiltrating complete SQL databases and leaking them on Telegram and Dark Web forums, and

Participating in coordinated DDoS waves against Israeli infrastructure within a broader hacktivist swarm.

Analyst assessment: Cyber Fattah should be treated as a state-aligned hacktivist proxy—a hybrid of ideological hacktivism and strategic information operations in support of Iranian regional objectives, with mid-tier but operationally effective web-exploitation capabilities.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-20

ATT&CK

MITRE ATT&CK

T1190Exploit Public-Facing Application
T1213Data from Information Repositories
T1486Data Encrypted for Impact
T1491.002External Defacement
T1498.001Direct Network Flood
T1505.003Web Shell
T1585.001Social Media Accounts
T1595.002Vulnerability Scanning

Research

Selected OSINT