Skip to content

Ababil of Minab

Key facts

Claimed incidents
1
Public claims
1

Overview

Ababil of Minab is a pro-Iranian cyber persona associated with data theft, destructive attacks and politically framed influence activity. It emerged publicly in late March or early April 2026, shortly after a cyber incident affected the Los Angeles County Metropolitan Transportation Authority. The persona initially presented itself as a newly formed, independent hacktivist collective acting in retaliation for civilian deaths in Minab, Iran. Its website, Telegram posts and victim announcements use explicitly pro-Iranian language, memorial imagery, threats and claims of disproportionate technical damage to frame its operations as ideological retaliation rather than financially motivated cybercrime.

The name appears to combine “Ababil,” a term with religious and military resonance in Iran, with Minab, a city in Hormozgan province. The group says its identity commemorates children killed in an attack on a school in Minab during the February 2026 conflict involving Iran, Israel and the United States. Its public-facing material describes the campaign as an effort to amplify the children’s voices and punish governments or organizations associated with Iran’s adversaries. This framing is important because it gives the persona an emotionally powerful founding narrative while connecting otherwise unrelated victims to a single retaliatory campaign.

Activity and targeting

The group’s first prominent public claim concerned LA Metro. On April 9, 2026, it published screenshots and video that appeared to show access to VMware virtualization infrastructure, Microsoft IIS servers and a rail-yard management display. It claimed to have destroyed 500 terabytes of data and exfiltrated 1 terabyte. Those quantities were not independently substantiated at the time, although LA Metro separately acknowledged detecting unauthorized network activity in March and taking systems offline. Subsequent forensic research reportedly located at least hundreds of gigabytes of LA Metro material on infrastructure associated with the attackers, supporting the underlying compromise while not validating every figure in the group’s announcement.

Ababil of Minab later claimed attacks against Vyncs, a vehicle and fleet-tracking platform; South Florida’s Tri-Rail commuter system; and UNIMAC, a Saudi construction and infrastructure company. The Vyncs claim included allegations that the attackers exfiltrated more than 4 terabytes, destroyed 250 terabytes, sent more than 1 million messages through the platform and defaced its website. Vyncs confirmed a serious service disruption and said systems had been taken offline, but the company did not publicly validate the claimed volumes of stolen or destroyed data. Tri-Rail also confirmed that it had been hacked, while saying the affected information was not critical. The UNIMAC claim emphasized the company’s alleged involvement with sensitive Saudi infrastructure, including work connected to a military installation, illustrating how the group uses a victim’s political or strategic associations to justify targeting it.

Research by Gambit Security found evidence of a broader campaign affecting organizations in the United States, Israel, Saudi Arabia and Turkey. Some victims—including an Israeli media organization, an Israeli educational institution and a Turkish insurance brokerage—apparently were not publicly named by the persona. That distinction suggests the public claims represent only the propaganda-facing portion of a larger intrusion operation. The attackers appear to conduct data exfiltration broadly while reserving destructive actions and public exposure for selected victims.

Methods and operational characteristics

The available reporting associates Ababil of Minab with a combined theft-and-destruction playbook rather than ordinary website defacement or distributed denial-of-service activity. The operators reportedly accessed virtualization management systems, databases, storage volumes and backup infrastructure. Destructive actions included deleting virtual machines, databases and storage resources through both scripts and direct hands-on-keyboard activity. Targeting several layers of the recovery environment makes restoration substantially harder than simply encrypting endpoint files because defenders must separately rebuild identity, virtualization, application, storage and backup systems.

The campaign also used dedicated exfiltration infrastructure and custom upload tooling. Gambit said it obtained forensic access to attacker staging infrastructure, while Hunt.io later reported finding an exposed server containing victim directories, command history, upload tools and several gigabytes of staged material. These findings provide stronger evidence of genuine intrusion capability than the screenshots posted through the group’s publicity channels. They also indicate that the operators were not merely reposting data obtained by another group or fabricating every compromise for attention.

At the same time, information operations are central to the persona’s behavior. Its announcements combine real access evidence with extreme destruction figures, inflammatory rhetoric, threatening language and carefully selected imagery. Some stated impacts have been partly corroborated, but others remain unverified or appear exaggerated. Dataminr assessed that this mixture of technical intrusion and psychological pressure is consistent with the broader Iranian “hacktivist” ecosystem, in which publicity, reputational harm and loss of confidence can be as important as the immediate technical effect.

What type of group is it?

Calling Ababil of Minab simply a hacktivist group is probably too literal. That is how the persona presents itself, and its propaganda is designed to resemble grassroots retaliatory hacktivism. However, the best available technical assessment indicates that it is more likely an Iranian state-aligned destructive cyber persona—or a front operated by or on behalf of an Iranian intelligence-linked intrusion team.

Gambit Security reported infrastructure and operational overlap with activity associated with Black Shadow, a cluster that Israel’s National Cyber Directorate has attributed to Iran’s Ministry of Intelligence and Security. Gambit therefore assessed that Ababil of Minab was unlikely to be a genuinely new, standalone collective. The research does not publicly establish the operators’ identities or prove that every action was directly ordered by the Iranian government, and Gambit was not the incident-response provider for the named victims. Nevertheless, the infrastructure links, hidden victim set, custom tooling, destructive tradecraft and resemblance to previously exposed Iranian personas provide substantially more support for state alignment than the group’s own independent-hacktivist story.

Incident claim

IT Curves attack claim followed paratransit disruption

View public claim
Incident date: Source: VECERT RadarPublished: Discovered:

Claim details

Ababil of Minab claimed in a June 9 post that it compromised IT Curves, affected 20 “critical machines,” wiped about 20 terabytes of data and exfiltrated roughly 2 terabytes of sensitive information. Confidence in those figures is low because they come solely from the group’s post and have not been independently verified. A review of the group’s claim site appear to show IT Curves-branded systems and files, which provides limited visual support for possible access, but the images do not establish when the access occurred, whether the material is authentic or whether the claimed scale of destruction and theft is accurate.

There is moderate confidence that a real service disruption occurred because Allegany County publicly told Transit riders to reconfirm certain paratransit trips after a cybersecurity incident involving an unnamed third-party scheduling vendor. However, there is low confidence in directly linking that disruption to IT Curves because the county did not identify the vendor, and neither the county nor IT Curves confirmed that IT Curves was involved. There is also low confidence in attributing the incident to Ababil of Minab because no affected entity or law enforcement agency publicly confirmed the group’s involvement.

The group’s broader transportation-sector activity adds context but does not verify this claim. Security researchers have linked the Ababil of Minab persona to other transportation-related intrusions and Iran-aligned infrastructure, giving the allegation some contextual credibility. Still, confidence remains low to moderate overall until IT Curves, Allegany County, law enforcement or another authoritative source confirms the compromise, affected systems, data theft, data wiping or threat actor.

Impacted organizations

Impacted locations

Source