Beyond Defacement: Inside 313 Team's Hacktivist and Ransomware Operations
Armed conflicts have long extended beyond conventional battlefields, and in recent years cyberspace has become an increasingly important front in that struggle. Across the Middle East, groups aligned with various resistance movements have embraced cyber operations to amplify political messaging, disrupt perceived adversaries, and project influence beyond geographic borders. Website defacements, coordinated propaganda campaigns, and increasingly sophisticated cyber capabilities have become part of a broader digital strategy, allowing these actors to reach global audiences while demonstrating their presence in an evolving cyber landscape.
Among the groups operating in this space is 313 Team, an Iraqi hacktivist collective that has consistently linked its activities to the broader narrative of the Islamic Resistance. While the group's public image is largely built around high-profile website defacements carrying ideological messages, its online footprint suggests a more structured operation than its defacement campaigns alone might imply. Over time, the group has developed a recognizable digital identity across multiple platforms, maintaining a persistent presence while promoting its operations through coordinated messaging and branded content.
This report examines that wider ecosystem through the lens of StealthMole's intelligence capabilities. Rather than focusing on a single incident, the investigation pieces together the group's digital infrastructure, operational footprint, claimed offensive capabilities, and relationships within the broader hacktivist landscape. By correlating evidence from multiple sources, the report provides a closer look at how 313 Team presents itself, how it operates, and how its activities extend beyond the defacement campaigns that first brought the group into view.
The Digital Face of the Islamic Resistance
Investigations into threat actors often begin with a single indicator that appears routine at first glance but reveals a much larger story when examined more closely. In this case, the investigation began within StealthMole's Defacement Alert module while monitoring website defacement activity linked to hacktivist groups operating in the Middle East.
Among the recorded incidents was a defacement attributed to 313 Team, involving a Russian website. According to StealthMole's records, the incident was detected on 8 September 2023, making it one of the earliest observable activities associated with the group within the platform. While a single website defacement would not normally warrant an extensive investigation, the group's distinctive name and ideological branding suggested that there was likely more to uncover than an isolated attack.
- http://in*******oy.ru
Rather than treating the defacement as a standalone event, the investigation shifted toward understanding the identity behind 313 Team. The next step was to determine whether the group maintained a broader online presence, particularly on platforms commonly used by hacktivist organizations to claim responsibility for attacks, distribute propaganda, and communicate with supporters. Using StealthMole's Telegram Tracker, a search for "313 Team" quickly revealed an active Telegram channel.
- https://t.me/**313*****m
The channel immediately provided the first glimpse into the group's public identity. Rather than presenting itself simply as a hacking collective, the operators described themselves as the "Iraqi Cyber Army" and incorporated religious and ideological references throughout their profile, including "جنود الإمام المهدي" ("Soldiers of Imam al-Mahdi") alongside the hashtags #Free_Palestine and #Ya_Mahdi. The channel biography also pointed investigators toward additional Telegram assets, suggesting that the group maintained multiple communication channels to support its operations and preserve its online presence.
- @**313******k
- @**313*******up
These initial findings indicated that 313 Team was far more than a name attached to a defacement page. The group's branding, ideological messaging, and interconnected Telegram presence pointed toward a coordinated online ecosystem rather than a collection of isolated attacks. With the primary communication channel identified, the investigation shifted from establishing the group's existence to mapping the infrastructure, operational footprint, and digital assets supporting its activities.
Beyond the Mirror: Mapping 313 Team's Digital Infrastructure
With the group's primary Telegram channel identified, the investigation shifted towards uncovering the digital infrastructure that sustained its operations. Rather than examining individual attack claims, the focus turned to understanding how 313 Team maintained its online presence, communicated with supporters, and preserved continuity despite the risk of account removals and platform enforcement. Using StealthMole's Telegram Tracker as the primary pivot point, a much broader ecosystem began to emerge.
The first indication that 313 Team operated through multiple communication channels came directly from the biography of its primary Telegram channel, https://t.me/**313*****m. Alongside describing itself as the "Iraqi Cyber Army," the channel promoted two additional Telegram assets. While these references initially appeared to be simple backup links, further investigation revealed that each served a distinct operational purpose.
- @**313*********k
- @**313*********up
The @**313*********up channel functioned as a resilience mechanism whenever Telegram removed the group's primary presence. One announcement explicitly informed followers that the original 313 Team channel had been taken down for the second time and directed them to migrate to the backup channel so they could continue following future operations. Rather than disrupting the group's activities, platform enforcement had been anticipated, with alternative channels already in place to preserve its audience and maintain operational continuity.
A different role emerged for @**313*********k, which was used to distribute material allegedly obtained during cyber operations. Posts within the channel contained download links, passwords, and references to archived data, while repeatedly directing followers back to the backup channel to ensure continued access if additional channels were removed. The coordinated cross-promotion between these Telegram assets demonstrated a deliberate effort to separate operational announcements from the publication of alleged stolen material while keeping followers connected across multiple platforms.
The investigation uncovered another public-facing channel, https://t.me/Team313******l, which primarily served as a showcase for the group's operations. Unlike the leak channel, posts here focused on announcing newly compromised websites, publishing screenshots of defacements, and highlighting the group's claimed successes. The consistent branding, language, and visual identity closely matched the primary Telegram channel, reinforcing the relationship between these assets.
Beyond Telegram itself, 313 Team maintained a presence across several external platforms that further strengthened attribution. The group's X account, mirrored the same ideological messaging and directed visitors back to its Telegram ecosystem, creating a bridge between mainstream social media and its primary communication platform. The investigation also identified the ProtonMail address, which appeared alongside the group's public messaging and represents a valuable attribution artifact that may assist future investigations involving the same operators.
- Twitter: https://x.com/**313****m
- Email: O********m@protonmail.com
Archived defacement records provided another layer of corroboration. Pages preserved on Mirror-H and OwnzYou displayed the same visual identity found throughout the Telegram ecosystem, including the group's logo, ideological slogans, references to the Iraqi Cyber Army, and direct links back to its social media accounts. Rather than existing as isolated mirrors of individual attacks, these archives connected the group's public claims with a consistent digital identity that persisted across multiple platforms.
- Mirror-H: https://mirror-h.org/mirror/5******8/
- OwnzYou: https://ownzyou.com/mirror/6c5*************896.html
The investigation also identified the public GitHub repository together with its associated GitHub Pages site, both promoting 313 HackBar v1.3. The project described functionality commonly associated with penetration testing, including SQL injection testing, cross-site scripting (XSS), fuzz testing, encoding utilities, and hash generation. While the repository was promoted through the group's Telegram channel, the available evidence does not independently establish that 313 Team developed the project. Nevertheless, its promotion demonstrates that the group's online presence extended beyond propaganda and attack claims to include publicly accessible technical resources.
- GitHub: https://github.com/313Team/313-HackBar
- GitHub Pages: https://313team.github.io/313-HackBar/
Another noteworthy discovery was the Telegram channel, operating under the name Team_313_Umar_Al_Khattab. Unlike the group's primary channels, this account predominantly shared cryptocurrency-related tools and blockchain utilities rather than attack announcements. Although the available evidence suggests a relationship with the wider 313 Team ecosystem, it does not conclusively establish that it is operated by the same administrators. As such, it is best regarded as an associated channel pending further corroboration.
- https://t.me/r****ll
These findings reveal a far more structured digital ecosystem than a single defacement channel. Telegram served as the operational hub, while backup channels, leak channels, social media accounts, archived defacement platforms, public code repositories, and associated communication channels collectively reinforced the group's online resilience.
Each platform fulfilled a specific role, allowing 313 Team to preserve its visibility, distribute content, and maintain continuity even when individual accounts or posts were removed. By correlating these disparate artifacts, StealthMole transformed what initially appeared to be a single Telegram channel into a mapped digital infrastructure supporting the group's broader cyber operations.
More Than Defacement: Following the Ransomware Trail
While mapping the group's digital infrastructure, one recurring term began appearing across multiple Telegram posts and defacement messages: 313 Ransomware. Initially, it appeared to be little more than another piece of branding accompanying the group's propaganda. However, as additional messages were uncovered through StealthMole's Telegram Tracker, it became evident that the name was repeatedly associated with claims of system encryption rather than simple website defacements, suggesting that 313 Team sought to project capabilities beyond those typically associated with hacktivist campaigns.
To better understand this recurring reference, the investigation pivoted by searching "313 Ransomware" within StealthMole's Telegram Tracker. The search led back to the group's own Telegram channel, where a detailed post titled "313 Ransomware" offered the clearest insight yet into the capability the group claimed to possess. Unlike previous announcements celebrating website compromises or service disruptions, this post adopted a distinctly technical tone, describing what it portrayed as the ransomware's encryption process.
According to the Telegram post, the ransomware begins by enumerating every available drive before recursively traversing directories across the compromised system. For each file encountered, it claims to generate a unique ChaCha20 encryption key together with a corresponding nonce. Rather than encrypting files in their entirety, the post describes a partial encryption strategy in which one byte is encrypted followed by two bytes left unencrypted, a technique intended to balance encryption speed with the ability to render files unusable. The generated ChaCha20 keys and nonces are then said to be encrypted using Elliptic Curve Integrated Encryption Scheme (ECIES) before being prepended to each encrypted file.
The group further attempted to justify these design choices by claiming that ChaCha20 enabled efficient stream-based encryption while ECIES provided security comparable to RSA with shorter key lengths and improved performance. Whether these technical claims accurately reflect a functioning ransomware family cannot be determined solely from the Telegram post, and no malware sample was recovered during this investigation. Nevertheless, the level of technical detail distinguishes this announcement from the group's typical ideological messaging and indicates an effort to portray 313Ransomware as a credible operational capability rather than simply a symbolic name.
The ransomware branding was not confined to this single technical post. Earlier artifacts collected during the investigation showed the same name appearing repeatedly across the group's public messaging. An archived defacement warned that targeted organizations would have their databases leaked and website files encrypted using 313 Ransomware. Rather than presenting the operation as a conventional website defacement, the message framed it as part of a broader campaign involving data theft, encryption, and continued attacks against national infrastructure.
Historical Telegram messages further reinforced this narrative. One post describing an attack against the Abha Palace Hotel claimed that the group had not only defaced the website but also copied internal systems, extracted databases, deleted backups, and encrypted affected infrastructure using 313 Ransomware before publishing credentials required to access the allegedly stolen data. While these statements remain claims made by the group and were not independently verified during the investigation, they demonstrate that the ransomware branding had been integrated into the group's public operations well before the technical description was published.
A similar pattern emerged in messages directed toward other organizations. During a claimed attack against Ubuntu, 313 Team asserted that the target's servers and user systems remained completely frozen and instructed the organization to negotiate through the encrypted messaging platform Session, publishing the following identifier:
- Session ID: 0574b***********************************5f0a
The post concluded by demanding that Ubuntu establish contact to negotiate what it described as a "permanent ceasefire." Another message addressed directly to eBay claimed that the company had already received an email containing the group's Session contact details and warned that attacks would continue until communication was established. Although neither incident could be independently verified through the available evidence, both messages closely resemble the negotiation tactics commonly employed by ransomware operators, where encrypted communication channels are provided for victim contact following an attack.
These findings suggest that 313 Team deliberately cultivated an identity extending beyond ideological defacement campaigns. Through repeated references to 313 Ransomware, technical explanations of its claimed encryption process, public extortion messages, and the publication of a dedicated Session identifier for negotiations, the group consistently portrayed itself as capable of conducting disruptive operations involving data theft, encryption, and victim negotiation.
While the investigation does not independently confirm the existence or effectiveness of the ransomware itself, it demonstrates that 313Ransomware had become a central component of the group's public operational narrative, marking a notable evolution from symbolic defacement activity toward messaging more commonly associated with ransomware operations.
More Than a Hacker Collective: Decoding 313 Team's Narrative
Throughout the investigation, one observation became increasingly clear: 313 Team consistently portrays itself as more than a conventional hacking group. While its activities revolve around cyber operations, the language, symbolism, and messaging surrounding those operations suggest that the group views cyberspace as an extension of a broader ideological struggle rather than simply another domain for conducting attacks.
This identity is established from the moment the group introduces itself. Across its Telegram channels, 313 Team repeatedly refers to itself as the "Iraqi Cyber Army" and "The Islamic Cyber Resistance in Iraq", while incorporating religious phrases such as "جنود الإمام المهدي" ("Soldiers of Imam al-Mahdi") and hashtags including #Ya_Mahdi and #Free_Palestine. The group's logo further reinforces this identity, featuring a raised hand holding an assault rifle above a globe alongside the Quranic verse, "Permission [to fight] has been given to those who are fought because they have been wronged" (Quran 22:39). Rather than functioning as decorative imagery, these elements frame the group's cyber operations as part of a larger religious and political narrative centered on resistance.
The significance of the name 313 also appears to support this narrative. Within Shia Islamic tradition, the number is commonly associated with the 313 companions of Imam al-Mahdi, who are believed to stand alongside him before the final establishment of justice. Although the group has not explicitly explained its choice of name, the repeated references to Imam al-Mahdi throughout its public messaging strongly suggest that the branding was chosen deliberately to reinforce this symbolic identity. The result is a consistent image of a cyber collective seeking legitimacy through religious symbolism rather than presenting itself simply as a group of hackers.
The targets highlighted throughout the group's public messaging further illustrate how it seeks to position its operations. Many of the claimed attacks involve organizations that the group associates with its political narrative, including Saudi government services, Israeli entities, and companies perceived as supporting opposing interests. At the same time, the investigation also identified claims involving international technology companies and commercial organizations such as Microsoft 365, Ubuntu, and eBay. This broader range of targets suggests that the group's messaging is not confined solely to government institutions. Instead, its public narrative portrays cyber operations against both public and private organizations as legitimate acts of resistance whenever they are believed to serve the group's broader ideological objectives.
Equally revealing is the language used to describe these operations. Throughout the Telegram posts examined during this investigation, attacks are rarely portrayed as criminal acts or opportunities for financial gain. Instead, they are consistently framed as acts of retaliation, resistance, or justice carried out on behalf of a wider cause. Even messages directed toward alleged victims adopt the language of conflict rather than conventional cybercrime. During the claimed attack against Ubuntu, for example, the group instructed the organization to negotiate a "permanent ceasefire" through an encrypted Session channel, while messages directed at eBay warned that attacks would continue until communication was established. This choice of language mirrors the rhetoric of armed conflict, reinforcing the group's effort to present itself as a participant in an ongoing struggle rather than a traditional ransomware operation.
The investigation also showed that 313 Team's Telegram ecosystem serves purposes extending well beyond announcing cyberattacks. Alongside operational updates, the group distributed technical resources such as the VigilAir drone detection document and the Naem Spy System Mehrdad Rahimi Contacts directory. The presence of these documents within the group's channels suggests an attempt to position Telegram as a broader repository for technical knowledge, operational resources, and intelligence-related material. This combination of propaganda, technical content, and operational announcements helps cultivate an image of an organized movement rather than a collection of isolated actors.
These observations indicate that 313 Team places as much emphasis on shaping perception as it does on claiming cyber operations. Its messaging consistently blends religious symbolism, political narratives, technical content, and cyber activity into a unified public identity. Whether announcing a website defacement, promoting what it describes as 313Ransomware, or distributing technical material through Telegram, every communication reinforces the same overarching message: that the group's cyber activities are intended to be viewed not as isolated hacking incidents, but as contributions to what it describes as the broader Islamic cyber resistance.
Conclusion
What began as the investigation of a single website defacement ultimately revealed a far more structured and deliberate cyber operation. By correlating evidence across StealthMole's Defacement Alert and Telegram Tracker, the investigation uncovered an interconnected ecosystem extending well beyond isolated attack claims. Telegram channels, backup infrastructure, defacement archives, public code repositories, communication identifiers, and ransomware-related messaging collectively paint the picture of a group that has invested considerable effort in building and maintaining a recognizable digital presence.
The investigation also demonstrates that 313 Team actively cultivates an identity that combines ideological messaging with cyber operations. Rather than portraying its activities as ordinary cybercrime, the group consistently frames its operations within the broader narrative of the Islamic Resistance, using religious symbolism, political messaging, and coordinated propaganda to reinforce that identity. Its repeated references to 313Ransomware, public negotiation messages, and technical discussions further suggest an effort to project capabilities extending beyond website defacements, even where those capabilities cannot be independently verified through the available evidence.
Perhaps the most important outcome of this investigation is not the confirmation of any single attack, but the ability to connect fragmented pieces of publicly available information into a coherent operational profile. Viewed individually, a defacement page, a Telegram post, or a GitHub repository may appear insignificant. Examined together, however, they reveal how 313 Team communicates, how it sustains its online presence, and how it seeks to shape perceptions of its own capabilities. That broader understanding provides a stronger foundation for future monitoring than any individual attack claim alone.
Editorial Note
Cyber threat investigations rarely produce absolute answers. Public claims, defacement pages, and online personas often mix verified activity with exaggeration, making careful attribution essential. This investigation demonstrates how StealthMole enables analysts to move beyond isolated indicators by correlating infrastructure, communications, and digital artifacts across multiple sources. While the operational picture surrounding 313 Team will undoubtedly continue to evolve, documenting and connecting these observable elements provides valuable context for understanding both the group's current activities and its future trajectory.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com
Labels: Featured, Hacktivist Group