Trending
ee-track">
Link copied!

Table of Contents

313 Team threat actor profile

Threat Actor Profile: 313 Team 

313 Team, also known as the Islamic Cyber Resistance in Iraq, is a pro-Iranian hacktivist collective associated with politically and religiously motivated cyber operations. The group presents itself as part of the broader cyber “resistance axis” and has publicly expressed support for Iran, the Islamic Revolutionary Guard Corps (IRGC), Hezbollah, Ansar Allah (Houthis), the Syrian government, and Russia. 

The group’s activity is primarily characterized by distributed denial-of-service (DDoS) attacks against websites and internet-facing services. Its stated targeting priorities include Israeli organizations and entities belonging to countries viewed as supporting or cooperating with Israel. These have included organizations in NATO member states and Gulf countries, as well as Jordan and Egypt. 

313 Team frames its operations as a form of cyber resistance in support of Palestine and Islam. Although its rhetoric frequently emphasizes government and strategic targets rather than civilian populations, its operations against publicly accessible services can still disrupt the availability of services used by businesses and the general public. 

Origin, Targets, and Operational Reach 

313 Team is associated with Iraq and has primarily positioned itself within the pro-Iranian regional hacktivist ecosystem. Its declared targeting is strongly influenced by geopolitical developments, particularly relationships with Israel and Iran. 

Known target countries include Iraq, Spain, Saudi Arabia, and the United States. The group has also identified a broader set of countries and organizations as potential targets based on their political alignment or cooperation with Israel. 

Its observed or reported target industries span several areas: 

  • Government and Law Enforcement 
  • Hospitality 
  • Professional Services 
  • Telecommunications 
  • Transportation and Logistics 
  • Other publicly exposed organizations and infrastructure 

The group is also linked to Yemen Cyber Army, indicating overlap within a wider network of ideologically aligned hacktivist actors. 

313 Team’s operations are primarily disruptive rather than focused on long-term covert access. Its activity is therefore more closely associated with availability attacks, reconnaissance, and opportunistic exploitation than with the persistent intrusion model typically associated with espionage-oriented APT groups. 

Operational Capabilities 

313 Team’s known activity can be broadly divided into reconnaissance, exploitation of exposed applications, and network-level disruption. 

  • Network Denial of Service – DDoS activity represents the group’s most prominent operational capability. The objective is to overwhelm publicly accessible resources with malicious traffic, reducing or completely interrupting availability. Websites and other internet-facing services can become inaccessible when their bandwidth, network infrastructure, or supporting services are saturated. 
  • Exploitation of Public-Facing Applications – The group is associated with attempts to exploit weaknesses in internet-facing applications and systems. Publicly exposed websites, web servers, and other services can provide opportunities for disruption or unauthorized access when vulnerabilities or misconfigurations are present. 
  • Victim Identity Reconnaissance – 313 Team may collect information about individuals and organizations before selecting targets. Publicly available information can reveal employee identities, organizational structures, usernames, authentication-related information, and other details useful for targeting. 
  • Victim Host Reconnaissance – Information about exposed hosts and infrastructure can help identify potential targets and determine which systems or services are accessible from the internet. Host information may include technologies in use, operating systems, exposed applications, and configuration details. 

Attack Methodology 

313 Team’s operational model is centered on politically motivated disruption. An operation may begin with reconnaissance intended to identify organizations, personnel, domains, and internet-facing infrastructure associated with a targeted country or institution. 

The group can then identify publicly accessible applications and services that may be vulnerable to exploitation or suitable for disruption. Reconnaissance of victim infrastructure can help determine which systems are exposed and which services may have the greatest operational or symbolic impact if disrupted. 

For DDoS campaigns, the primary objective is to degrade availability rather than maintain prolonged access. High volumes of malicious traffic can be directed toward websites, network connections, or supporting infrastructure. Distributed traffic sources can make filtering and attribution more difficult and may allow attackers to sustain pressure against the target. 

Where exposed applications contain exploitable weaknesses, attackers may also attempt to leverage those weaknesses for initial access. MITRE ATT&CK maps this activity to Exploit Public-Facing Application (T1190). 

The group’s targeting is heavily influenced by political events and regional conflicts. Consequently, organizations that become associated with a particular government, diplomatic position, or cooperation agreement may become targets even when they are not directly involved in the underlying political dispute. 

Defensive Considerations 

Organizations facing activity associated with 313 Team should prioritize the availability and resilience of externally exposed services. Internet-facing applications should be regularly patched, securely configured, and continuously monitored for unexpected changes or suspicious activity. 

DDoS protection should be implemented for critical public-facing services, with appropriate traffic filtering, rate limiting, upstream mitigation, and redundant infrastructure where operationally necessary. Organizations should also monitor reconnaissance against exposed assets and maintain an accurate inventory of internet-facing domains, applications, and infrastructure. 

Because the group’s targeting is strongly influenced by geopolitical developments, organizations with direct or perceived political associations may face elevated exposure during periods of regional tension. Security teams should therefore combine technical monitoring with threat-intelligence tracking to identify changes in targeting and campaign activity. 

MITRE ATT&CK Techniques Mapped to 313 Team

  • Initial Access – Exploit Public-Facing Application (T1190): 313 Team may exploit vulnerabilities or misconfigurations in internet-facing applications, websites, servers, and other exposed services to gain initial access. 
  • Impact – Network Denial of Service (T1498): The group conducts network-level DDoS attacks to overwhelm bandwidth or network resources and disrupt access to targeted websites and online services. 
  • Reconnaissance – Gather Victim Identity Information (T1589): 313 Team may collect information about targeted organizations and personnel, including publicly available identity data, usernames, credentials, and authentication-related details. 
  • Reconnaissance – Gather Victim Host Information (T1592): The group may gather information about exposed hosts and infrastructure, including operating systems, applications, configurations, and other technical details that can support target selection and follow-on activity. 

Conclusion 

313 Team represents a politically motivated hacktivist threat whose operations are primarily intended to create disruption and demonstrate ideological alignment. Its reliance on reconnaissance, exploitation of exposed applications, and network-level denial-of-service attacks means that organizations with publicly accessible services can remain potential targets. 

The group’s activity differs from conventional espionage-focused APTs. Rather than emphasizing stealthy, long-term persistence, 313 Team’s operations are generally focused on visibility, disruption, and political messaging.  

Maintaining resilient public-facing infrastructure, monitoring exposed assets, and preparing effective DDoS response capabilities can reduce the potential impact of future campaigns. 

They’re watching your attack surface. Are you watching them? Cyble Threat Intelligence platform helps security teams track threat actors, exposed infrastructure, and emerging campaigns—so they can see the threat before it becomes an incident. 

See the threat. Know the target. Stay ahead with Cyble. 

Frequently Asked Questions (FAQs) 

What is 313 Team? 

313 Team, also known as the Islamic Cyber Resistance in Iraq, is a pro-Iranian hacktivist collective associated with politically and religiously motivated cyber operations. 

What does 313 Team target? 

The group has identified Israeli entities and organizations in countries perceived to support or cooperate with Israel as potential targets. Reported target countries include Iraq, Spain, Saudi Arabia, and the United States. 

What industries are targeted? 

Reported sectors include government and law enforcement, telecommunications, hospitality, professional services, transportation, and logistics. 

What is 313 Team’s primary attack method? 

DDoS attacks are the group’s most prominent operational capability, with attacks intended to disrupt the availability of public-facing websites and services. 

Does 313 Team exploit vulnerabilities? 

The group is associated with Exploit Public-Facing Application (T1190), indicating that exposed applications and services can be targeted when vulnerabilities or misconfigurations provide an opportunity for access. 

Which MITRE ATT&CK techniques are associated with the group? 

Documented techniques include Gather Victim Identity Information (T1589), Gather Victim Host Information (T1592), Exploit Public-Facing Application (T1190), and Network Denial of Service (T1498). 

What should organizations do to defend against 313 Team? 

Organizations should patch internet-facing applications, maintain accurate external attack-surface inventories, deploy DDoS protection, monitor exposed infrastructure, and maintain an incident-response plan for politically motivated disruption campaigns. 

Media Disclaimer: This profile is based on the supplied threat-intelligence information and associated MITRE ATT&CK technique descriptions. It is intended for cybersecurity research, threat awareness, detection engineering, and defensive planning. Organizations should independently validate attribution, indicators, targeting information, and campaign details before using them for operational security decisions. 

Discover how we help proactively defend against evolving threats with Gen 3 intelligence. Request a Demo today!

Share Post:

Stay Informed

The Cyber Briefing Security Teams Actually Read!

Join security teams across 50+ countries getting Cyble's weekly research, advisories, and analyst insights.

No spam, ever. Unsubscribe anytime.

Related Topics

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams