Predatory Sparrow — Hacktivist Profile

Predatory Sparrow, which signs its Persian-language claims as Gonjeshke Darande, emerged in 2021 and describes itself as a hacktivist collective, though its known record consists of destructive sabotage aimed squarely at Iranian critical infrastructure. Its first public operation paralysed Iran's rail network on 9 July 2021; SentinelOne analysed the wiper involved, named it Meteor, and stated plainly that it could not tie the intrusion to any previously identified group. The group claimed the 26 October 2021 outage that left roughly 4,300 Iranian filling stations unable to take payment and turned public billboards into anti-government slogans, and a comparable strike on fuel distribution followed in December 2023 according to Wired's reporting. Its most physical operation came on 27 June 2022 against Iranian steel production, publicised with footage the group presented as molten metal spilling inside a plant; Wired also reported the subsequent dumping of tens of thousands of internal emails from Iranian steel firms. Reuters reported that in June 2025 the group hit Bank Sepah and then the exchange Nobitex, where roughly $90 million in cryptocurrency was taken and rendered unrecoverable. Israeli sponsorship is widely assumed and the New York Times cited two Pentagon officials linking the 2021 fuel attack to Israel, but no government has acknowledged the group.

Also tracked as

Gonjeshke Darande, گنجشک درنده, Indra

IntelFusions coverage (1)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions