Cyberwarriors or State Agents? Predatory Sparrow’s Israel Ties Examined

Cyberwarriors or State Agents? Predatory Sparrow’s Israel Ties Examined
  • calendar_today September 3, 2025
  • Technology

Once again, Iran is facing a strong cyberattack campaign, this time with a ferocity targeted squarely at the financial core of the country. Launching twin strikes on Wednesday, the hacker group Predatory Sparrow compromised banking systems, deleted private financial information, and destroyed tens of millions in cryptocurrencies.

First arrived the hit to Iran’s biggest bitcoin exchange, Nobitex. Unlike conventional tips meant to profit from fund syphoning, this one had completely different objectives: eradication. Leading blockchain analysis company Elliptic verified that deliberate destruction of more than $90 million in cryptocurrency occurred. The attackers directed the money into personalized “vanity” wallets, each with inflammatory labels like “FuckIRGCterrorists,” a message clearly meant to sting.

“These addresses are not usable by anyone,” co-founder of Elliptic Tom Robinson, said. “There isn’t any recovery.” The money has vanished just here. One of the few times we have seen where crypto was purposefully burned for political ends is here.

Publicly accusing Nobitex of being a tool for Iran’s government, Predatory Sparrow helped the country avoid sanctions and support terrorism by The hackers and Elliptic claimed that Nobitex was discovered to have links to wallets connected to IRGC operatives, Hamas, the Houthi rebels, and Palestinian Islamic Jihad.

The Nobitex website vanished from the internet shortly following the attack. No warning existed. None of anything. Many of the users, who depend on the platform as a defense against Iran’s inflation-ridden currency, were left in uncertainty.

Still, that was only one aspect. A second cyberattack followed just hours later—this time on Sepah Bank, one of the nation’s most prominent financial institutions. Tied closely to the Islamic Revolutionary Guard Corps (IRGC) and Iran’s military-industrial network, Sepah plays a crucial role in facilitating transactions for state defense projects.

Predatory Sparrow claimed they had erased all internal data and provided leaked documents to back up the claim. These documents appear to show the bank’s cooperation with the ballistic missile program and other military initiatives under the regime.

A warning was attached to the post: “Caution: Cooperating with instruments of sanctions evasion and terror financing is not good for your long-term financial health. Who’s next?”

According to Hamid Kashfi, a Sweden-based cybersecurity expert with contacts in Iran, the fallout was swift. “Sepah’s ATMs went down. People couldn’t access their accounts. It’s widespread chaos,” he said. “It’s not just hurting the regime—it’s affecting average citizens.”

While Sepah Bank’s website briefly came back online, reports suggest the internal systems remain largely nonfunctional. The Iranian government has declined to respond publicly to the attack or the allegations raised.

Predatory Sparrow—also known by its Farsi alias Gonjeshke Darande—has a history of hitting critical Iranian infrastructure. The group previously paralyzed Iran’s fuel distribution network, caused rail delays, and in one of the most shocking cases, sabotaged a steel mill, releasing molten metal across the factory floor and igniting a fire.

Their operations are high-profile, methodical, and often backed by evidence they leak themselves. Despite their local branding, most cybersecurity experts are convinced Predatory Sparrow is backed by Israel’s intelligence community.

“This group is one of the few in the world that not only makes serious threats, but has the technical muscle to deliver on them,” said John Hultquist, chief analyst at Google’s Mandiant. “Their attacks are deeply strategic and often timed to coincide with real-world tensions.”

Striking Nobitex and Sepah Bank sends a message beyond financial destruction. These two institutions represent Iran’s workaround to the global financial system and its domestic military machine. Their compromise is a clear threat to Iran’s digital sovereignty.

And with Predatory Sparrow signing off with “Who’s next?”—this might be just the beginning.