Ababil of Minab is a pro-Iranian cyber persona associated with data theft, destructive attacks and politically framed influence activity. It emerged publicly in late March or early April 2026, shortly after a cyber incident affected the Los Angeles County Metropolitan Transportation Authority. The persona initially presented itself as a newly formed, independent hacktivist collective acting in retaliation for civilian deaths in Minab, Iran. Its website, Telegram posts and victim announcements use explicitly pro-Iranian language, memorial imagery, threats and claims of disproportionate technical damage to frame its operations as ideological retaliation rather than financially motivated cybercrime.
The name appears to combine “Ababil,” a term with religious and military resonance in Iran, with Minab, a city in Hormozgan province. The group says its identity commemorates children killed in an attack on a school in Minab during the February 2026 conflict involving Iran, Israel and the United States. Its public-facing material describes the campaign as an effort to amplify the children’s voices and punish governments or organizations associated with Iran’s adversaries. This framing is important because it gives the persona an emotionally powerful founding narrative while connecting otherwise unrelated victims to a single retaliatory campaign.
Activity and targeting
The group’s first prominent public claim concerned LA Metro. On April 9, 2026, it published screenshots and video that appeared to show access to VMware virtualization infrastructure, Microsoft IIS servers and a rail-yard management display. It claimed to have destroyed 500 terabytes of data and exfiltrated 1 terabyte. Those quantities were not independently substantiated at the time, although LA Metro separately acknowledged detecting unauthorized network activity in March and taking systems offline. Subsequent forensic research reportedly located at least hundreds of gigabytes of LA Metro material on infrastructure associated with the attackers, supporting the underlying compromise while not validating every figure in the group’s announcement.
Ababil of Minab later claimed attacks against Vyncs, a vehicle and fleet-tracking platform; South Florida’s Tri-Rail commuter system; and UNIMAC, a Saudi construction and infrastructure company. The Vyncs claim included allegations that the attackers exfiltrated more than 4 terabytes, destroyed 250 terabytes, sent more than 1 million messages through the platform and defaced its website. Vyncs confirmed a serious service disruption and said systems had been taken offline, but the company did not publicly validate the claimed volumes of stolen or destroyed data. Tri-Rail also confirmed that it had been hacked, while saying the affected information was not critical. The UNIMAC claim emphasized the company’s alleged involvement with sensitive Saudi infrastructure, including work connected to a military installation, illustrating how the group uses a victim’s political or strategic associations to justify targeting it.
Research by Gambit Security found evidence of a broader campaign affecting organizations in the United States, Israel, Saudi Arabia and Turkey. Some victims—including an Israeli media organization, an Israeli educational institution and a Turkish insurance brokerage—apparently were not publicly named by the persona. That distinction suggests the public claims represent only the propaganda-facing portion of a larger intrusion operation. The attackers appear to conduct data exfiltration broadly while reserving destructive actions and public exposure for selected victims.
Methods and operational characteristics
The available reporting associates Ababil of Minab with a combined theft-and-destruction playbook rather than ordinary website defacement or distributed denial-of-service activity. The operators reportedly accessed virtualization management systems, databases, storage volumes and backup infrastructure. Destructive actions included deleting virtual machines, databases and storage resources through both scripts and direct hands-on-keyboard activity. Targeting several layers of the recovery environment makes restoration substantially harder than simply encrypting endpoint files because defenders must separately rebuild identity, virtualization, application, storage and backup systems.
The campaign also used dedicated exfiltration infrastructure and custom upload tooling. Gambit said it obtained forensic access to attacker staging infrastructure, while Hunt.io later reported finding an exposed server containing victim directories, command history, upload tools and several gigabytes of staged material. These findings provide stronger evidence of genuine intrusion capability than the screenshots posted through the group’s publicity channels. They also indicate that the operators were not merely reposting data obtained by another group or fabricating every compromise for attention.
At the same time, information operations are central to the persona’s behavior. Its announcements combine real access evidence with extreme destruction figures, inflammatory rhetoric, threatening language and carefully selected imagery. Some stated impacts have been partly corroborated, but others remain unverified or appear exaggerated. Dataminr assessed that this mixture of technical intrusion and psychological pressure is consistent with the broader Iranian “hacktivist” ecosystem, in which publicity, reputational harm and loss of confidence can be as important as the immediate technical effect.
What type of group is it?
Calling Ababil of Minab simply a hacktivist group is probably too literal. That is how the persona presents itself, and its propaganda is designed to resemble grassroots retaliatory hacktivism. However, the best available technical assessment indicates that it is more likely an Iranian state-aligned destructive cyber persona—or a front operated by or on behalf of an Iranian intelligence-linked intrusion team.
Gambit Security reported infrastructure and operational overlap with activity associated with Black Shadow, a cluster that Israel’s National Cyber Directorate has attributed to Iran’s Ministry of Intelligence and Security. Gambit therefore assessed that Ababil of Minab was unlikely to be a genuinely new, standalone collective. The research does not publicly establish the operators’ identities or prove that every action was directly ordered by the Iranian government, and Gambit was not the incident-response provider for the named victims. Nevertheless, the infrastructure links, hidden victim set, custom tooling, destructive tradecraft and resemblance to previously exposed Iranian personas provide substantially more support for state alignment than the group’s own independent-hacktivist story.