Skip to main content
AVOID.NET

Predatory Sparrow (Gonjeshke Darande)

avoid.net/predatory-sparrow-gonjeshke-darande22/100·75% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·21wxqb…Wbea

Summary

Predatory Sparrow, known in Persian as Gonjeshke Darande, is a hacking group active since at least July 2021 that has claimed responsibility for a series of destructive cyberattacks against Iranian critical infrastructure, financial institutions, and cryptocurrency exchanges. The group is widely believed by security researchers, Israeli media, and anonymous U.S. defense officials to have links to the Israeli government, though Israel has never formally acknowledged any connection. Their operations are politically motivated, targeting entities alleged to support Iran's Islamic Revolutionary Guard Corps (IRGC) and facilitate sanctions evasion, and have extended directly into the cryptocurrency space with the June 2025 destruction of approximately $90 million in digital assets stolen from Iran's largest crypto exchange, Nobitex.

Have evidence about Predatory Sparrow (Gonjeshke Darande)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

Timeline(11 events)

9 July 2021

Predatory Sparrow disrupts Iran's national railway system using Meteor wiper malware, displaying mocking messages on station boards directing passengers to call Supreme Leader Khamenei's office.

SentinelLabs MeteorExpress Analysis

10 July 2021

Group attacks website of Iran's Ministry of Roads and Urban Development, one day after the railway attack.

Predatory Sparrow — Wikipedia

26 October 2021

Major cyberattack disrupts approximately 4,300 Iranian fuel stations (roughly 80% of national total), disabling subsidized fuel payment systems and hijacking highway billboards. Group claims responsibility; anonymous U.S. defense officials later attribute the operation to Israel.

2021 Iranian Fuel Cyberattack — Wikipedia

27 January 2022

Group claims responsibility for a wiper attack against Islamic Republic of Iran Broadcasting (IRIB), Iran's national public broadcaster.

Wiper Used in Attack on Iran National Media Network — SecurityWeek

27 June 2022

Coordinated cyberattacks hit three Iranian steel companies (Khuzestan Steel, Mobarakeh Steel, Hormozgan Steel) affiliated with the IRGC. Video footage of equipment damage, including a fire caused by molten steel spillage, is released. Khuzestan Steel suspends operations. Alleged internal documents are leaked.

Iranian steel facilities suffer apparent cyberattacks — CyberScoop

10 October 2023

Group reemerges after a nine-month hiatus, posting 'Do you think this is scary? We returned' on Telegram and X, coinciding with the aftermath of the October 7 Hamas attack on Israel.

Savvy Israel-linked hacking group reemerges amid Gaza fighting — CyberScoop

18 December 2023

Attack disrupts approximately 70% of Iranian gas stations during the December 2023 campaign. Iranian Oil Minister Javad Owji confirms the disruption. Group states the attack is in response to Islamic Republic aggression and its regional proxies.

Predatory Sparrow claim cyberattack on Iran's gas stations — CNBC

17 June 2025

Group claims to have attacked Bank Sepah, an Iranian state-owned bank with alleged IRGC ties, deploying wiper malware to destroy data at the primary data center. ATM and mobile banking services are disrupted across Iran. Operation occurs amid active Israel-Iran missile exchanges.

Pro-Israel hacktivist group claims responsibility for alleged Iranian bank hack — TechCrunch

18 June 2025

Group breaches Nobitex, Iran's largest cryptocurrency exchange, stealing approximately $90 million across multiple blockchains including Bitcoin, Ethereum, Dogecoin, XRP, Solana, Tron, and TON. Rather than retaining the funds, the group burns them by transferring to inaccessible vanity addresses bearing the phrase 'F*ckIRGCterrorists.' Elliptic confirms the breach and identifies Nobitex's prior transactions with IRGC-linked, Hamas-linked, and Houthi-linked wallets.

Iranian crypto exchange Nobitex hacked for over $90 million by pro-Israel group — Elliptic

19 July 2025

Reports confirm that wartime cyberattacks wiped data from two major Iranian banks, Sepah and Pasargad, with Sepah's primary data center going dark and stored data apparently corrupted.

Wartime cyberattack wiped data from two major Iranian banks — Iran International

2 June 2026

OFAC formally designates Nobitex and three other Iranian crypto exchanges (Wallex, Bitpin, Ramzinex) for sanctions evasion and terrorist financing, actions that analysts noted were compounded by on-chain evidence surfaced during and after the Predatory Sparrow breach.

OFAC Sanctions Nobitex and Iranian Cryptocurrency Exchanges — Chainalysis
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 31 of 31 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/15/2026, 5:38:24 PM

last updated: 8/26/2026, 5:06:01 AM

4 views

avoid.net — verified advice for a post-truth world