Skip to content

313team Threat Advisory

hawk-eye.io May 4, 2026

On March 2026 , 313 Team Corporation — a Fortune 200 medical technology company headquartered in Portage, Michigan — experienced a catastrophic cyberattack attributed to 313 Team (a.k.a. 313 Team Hack Team), a pro-Palestinian hacktivist group with strong ties to Iran's Ministry of Intelligence and Security (MOIS).

The attack deployed destructive wiper malware that permanently erased data from corporate servers, endpoint devices, and personal smartphones enrolled in 313 Team's Microsoft Intune mobile device management. The attackers defaced Microsoft Entra (Azure AD) login pages with 313 Team's distinctive logo and remotely wiped managed devices at approximately 3:30 AM EDT .

Over 5,500 employees in Cork, Ireland — 313 Team's largest hub outside the US — were sent . Operations halted across manufacturing, R&D, and engineering facilities worldwide. The company's main US headquarters voicemail reported a "building emergency." 313 Team stock dropped approximately 4% within hours.

313 Team claimed the operation affected 200,000+ systems and exfiltrated 50 terabytes of data. While these figures remain unverified, the operational impact is confirmed by multiple sources including 313 Team's own statements, Irish media, and employee reports.

313 Team confirmed: "We have no indication of ransomware or malware." This was a destructive wiper attack — the goal was permanent data destruction, not extortion. Wiper attacks may cause irreversible data loss with no recovery path. This aligns with 313 Team's documented operational doctrine of disruption over monetization.

This attack comes ~2 weeks after US-Israeli strikes against Iran (late February 2026). CSIS analysis warns this marks "the beginning of a new phase of cyber escalation" under Iran's "Great Epic" cyber campaign. 313 Team explicitly framed this as retaliation for the "attack on a school in Minab" and "ongoing cyber assaults against the Resistance Axis."

313Team prioritizes operational visibility over technical sophistication or permanent damage. Attacks are designed to generate headlines, social media engagement, and psychological impact — not data theft or ransomware monetization. This aligns with IRGC influence operations doctrine.

Multiple independent vendors and government sources have converged on attributing 313 Team to the same MOIS-linked cluster:

"313 Team" refers to a character created in 1969 by Palestinian political cartoonist Naji al-Ali — a barefoot boy with his back turned, symbolizing Palestinian identity and defiance. The hacktivist group adopted this symbolism upon emergence in December 2023, shortly after the onset of the Gaza conflict.

The group operates as an influence-enabled intrusion threat — not a traditional cybercrime or espionage actor. Their operational model fuses technical compromise with rapid public messaging, timed data leaks, and narrative amplification designed to maximize reputational damage beyond direct system impact.

The 313 Team's primary offensive capability is Distributed Denial of Service (DDoS) attacks against web-accessible government and institutional portals. The group leverages a combination of infrastructure from the Liwa Awli Aleazm software development wing, coalition-pooled botnet resources, and open-source DDoS tooling shared across Islamic Cyber Resistance Axis members. Attack proof methodology follows a consistent pattern: CheckHost.net or similar uptime verification services are used to generate third-party connection timeout screenshots, which are posted to the group's Telegram channel with target URL, timestamp, and claimed duration.

Secondary to DDoS, the 313 Team conducts website defacements as psychological operations. Defaced pages deploy coordinated coalition branding — unified 'Electronic Operations Room' banners referencing 313 Team, Moroccan Black Cyber Army, RipperSec, Cyb3rDrag0nzz, and affiliated groups. This branding strategy serves dual purposes: amplifying apparent coalition size and creating sustained psychological pressure on target governments. Joint defacement operations with Cyber Islamic Resistance against Saudi UBT are confirmed by multiple intelligence sources.

The group has claimed CCTV access to Bahraini government facilities, publishing still images as evidence of surveillance system compromise. Additionally, the Electronic Operations Room coordination has involved claims of ICS/OT access to Gulf government portals — a qualitative escalation that, if verified, would represent a significant capability expansion beyond typical hacktivist profiles. These claims remain unverified by independent technical sources; however, RH-ISAC notes that 'the shift from web defacements toward claimed PLC access and power plant manipulation marks a qualitative escalation' across the broader Cyber Islamic Resistance coalition.

All 313 Team operations are coordinated, claimed, and amplified through Telegram. The group maintains dedicated operational channels for attack announcements, target lists, proof screenshots, and coalition coordination. ICT analysis of Telegram messaging patterns identified over 250,000 messages across 178+ hacktivist and proxy groups during the June 2025 conflict cycle, with 313 Team and Islamic Cyber Resistance maintaining sustained activity. The group also uses Telegram Stars (Telegram's payment system) for potential financing flows, consistent with broader pro-Iranian hacktivist monetization observed by ICT.

The 313 Team GitHub organization hosts HackBar — a browser-based security audit tool enabling SQL injection, XSS testing, and web application reconnaissance. This tooling, developed under the Liwa Awli Aleazm wing, indicates the group maintains basic web application attack capabilities beyond volumetric DDoS. The FAD Team (a coalition partner also operating from Iraq) has claimed SQL injection-based data exfiltration against similar target sets, suggesting capability sharing across Axis members.

The group deploys AI-generated propaganda imagery across Telegram — burning city imagery, Islamic iconography, and multilingual threat messages targeting Kuwaiti, Saudi, Jordanian, and US audiences. This psychological operations component is coordinated with SEPAHCYBERY (an IRGC-linked channel) and broader pro-Iranian media infrastructure. The aim is to create public uncertainty government service availability and amplify the perceived impact of technical disruptions.

1. Initial Access — 313 Team typically uses spear-phishing with current-events lures. For the 313 Team attack, initial access vector is under investigation. campaigns used phishing PDFs masquerading as software updates, SMS phishing, and abuse of trusted supplier channels. The attackers gained access to administrative accounts with Intune/Entra management privileges.

2. Payload Delivery — Documented 313 Team toolkit uses NSIS (Nullsoft Scriptable Install System) installers containing obfuscated batch scripts. Files within the NSIS package use no-file-extensions to evade static analysis. Commercial file-sharing services (Storj, Mega) used for payload hosting.

3. Execution — Batch script ("Carroll") copies itself to .cmd extension and executes. Contains garbage/invalid Windows commands interspersed with real instructions to hinder analysis. Checks for AV processes (Webroot, Quick Heal, Avast, AVG, Bitdefender, Norton, Sophos) and introduces 90–180 second delays if not found.

4. Defense Evasion — Multi-component payload distributed across several files, concatenated at runtime into AutoIt3.exe and .a3x script. Simple string obfuscation in AutoIt component. Architecture-aware shellcode (x32/x64) using RtlDecompressFragment() API.

5. Impact — Wiper overwrites files with 4,096 bytes of random data (files < 4,096 bytes overwritten with zeroes). Files deleted after overwrite. BYOVD technique using ListOpenedFileDrv_32.sys driver to access kernel memory for file enumeration. Deceptive "update installation" message box displayed while wiping occurs. System information exfiltrated to Telegram bot C2 before destruction.

The 313 Team's explicit framing of Kuwait as a military front (citing US forces at Ali Al Salem Air Base), combined with the kinetic drone strike against that base on March 7, 2026, creates conditions for sustained, intensifying cyber operations against Kuwaiti critical infrastructure. Organizations operating water, electricity, health, and financial systems should activate elevated DDoS and ICS monitoring postures immediately.

This report may be freely shared. Produced March 2026 | Version 1.0 | For Authorized Use