Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Reappears” refers to Predatory Sparrow’s reported return online in October 2023, after about a year of silence—not to a verified new return in 2026. The group, also known as Gonjeshke Darande, has claimed high-profile attacks on Iranian targets, but those claims should be distinguished from independently confirmed impact. Public sources describe it as pro-Israel or anti-Iran and have reported suspected Israeli ties; they do not establish that the Israeli government directs it.

What does Predatory Sparrow’s “reappearance” refer to?

In an October 2023 cyber brief, the European Union Agency for Cybersecurity’s CERT-EU said Predatory Sparrow had re-emerged online after a year of silence, amid the Israel-Hamas conflict. The brief described the group as focused on Iran and characterized possible Israeli government ties as suspected, not confirmed. CERT-EU’s October 2023 brief is the source for that specific use of “reappeared.”

That dated description matters: it does not establish that the group had newly returned in 2026. A May 25, 2026 analysis reported no activity associated with Predatory Sparrow since the start of the joint US-Israel war in February 2026. Its author also described the group’s activity as intermittent and noted that limited reporting visibility, including Iranian internet restrictions, could help explain the gap. This is one analyst’s observation, not proof that the group is inactive. The May 2026 analysis

What attacks has the group claimed?

Predatory Sparrow’s claims have targeted Iranian organizations and infrastructure. The evidence differs by incident: a group announcement is not the same as independently verified responsibility, and reported disruption does not by itself establish the full extent or cause of damage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date and target What was claimed or reported What is established in the cited reporting
June 2022, three Iranian steel manufacturers The group claimed cyberattacks and alleged physical destruction, sharing video of an explosion. Mandiant reported the claims and said the techniques appeared more complex than those used by many hacktivists, potentially indicating collaboration or sponsorship. A later analysis said the precise operational details and claimed physical impact at the Khuzestan plant remain poorly documented.
June 17, 2025, Bank Sepah The group claimed it had destroyed data at the Iranian bank. TechCrunch reported customer access problems and branch closures, but said it could not independently verify the alleged cyberattack.
June 18, 2025, Nobitex cryptocurrency exchange The group said it stole and burned more than $90 million in cryptocurrency. CERT-EU reported the group’s claim. That figure is not an independently verified loss in CERT-EU’s account.

Sources: Mandiant on the 2022 steel claims; TechCrunch on Bank Sepah; CERT-EU on Nobitex; the May 2026 analysis.

How much of the steel-plant story is verified?

The 2022 episode drew attention because the group alleged physical damage at industrial facilities, not just disruption of websites or data. Mandiant said the reported techniques looked more sophisticated than those used by many hacktivists, but that observation does not identify who operated the group or prove state sponsorship.

Operational technology (OT) incidents need particular care in reporting. Mandiant has noted that hacktivists may claim physical effects as political messaging and that such claims can be difficult to validate. The later analysis said public reporting does not document the exact OT commands used in the steel incident or conclusively demonstrate the claimed physical damage at the Khuzestan plant. The group’s allegation, the explosion video, and assessments of technical sophistication should therefore not be treated as proof of a specific mechanism or verified physical outcome. Mandiant’s account; the May 2026 analysis.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is Predatory Sparrow controlled by Israel?

That has not been established by the cited public reporting. TechCrunch reported that the group’s identity remained unclear and that it presents itself as pro-Israel or anti-Iran. CERT-EU described possible Israeli government ties as suspected. Mandiant’s assessment that some techniques might indicate collaboration or sponsorship is not an attribution to a particular government.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those distinctions are important: a group’s stated politics, a suspected connection, and evidence of technical capability do not independently demonstrate command or control by a state. In a statement quoted by TechCrunch, Mandiant chief analyst John Hultquist wrote: “Despite appearances this actor is not all bluster.” That remark describes his assessment of the actor; it is not confirmation of Israeli government direction. TechCrunch’s report; CERT-EU’s brief; Mandiant’s analysis.

What to take from reports of the group’s activity

  • Read dates closely: the cited “reappearance” was reported in October 2023; the later record includes claimed operations in June 2025.
  • Separate claims from corroboration: the Nobitex amount and the steel facility’s physical damage were claims, not established measurements in the cited accounts.
  • Distinguish effects: access problems or closures are reported disruption, not automatic proof of the cause or of destructive impact.
  • Keep attribution qualified: public sources describe a pro-Israel or anti-Iran identity and suspected links, but do not establish Israeli government control.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.