313 Team is a hacktivist group that describes itself as the Islamic Cyber Resistance in Iraq. Its public identity is built around support for Palestine, Iran, and organizations associated with the Axis of Resistance. The group has claimed cyberattacks against government agencies, financial institutions, technology companies, media organizations, public services, and consumer platforms.
Most of its reported activity involves distributed denial-of-service (DDoS) attacks aimed at disrupting access to websites, applications, and other public-facing services. The group also promotes commercial attack services and criminal tools through channels associated with its operations.
VenariX considers 313 Team a credible hacktivist threat actor whose activity is primarily associated with distributed denial-of-service (DDoS) attacks. Of the incidents attributed to the group and recorded in the VenariX platform, 72% have been independently confirmed, indicating that its claims should not be dismissed as propaganda alone.

Background
313 Team describes itself as an Iraqi cyber group and uses the name Islamic Cyber Resistance in Iraq. The earliest publicly available information identified by VenariX dates to November 2024, although the group may have been active earlier. Public sources do not independently confirm the identities, locations, organizational structure, or state ties of its members.
313 Team’s name and public statements contain Shia religious references and language associated with the broader regional resistance movement. The number 313 likely refers to the companions who, in Shia tradition, are expected to support Imam al-Mahdi at the time of his reappearance. The group also references Imam Hussein and has expressed support for Iran, Hezbollah, Ansar Allah, and the broader Axis of Resistance.
Independent threat intelligence reporting has identified 313 Team as part of the pro-Iran hacktivist ecosystem and described its activity as focused primarily on DDoS attacks, service disruption, propaganda, and symbolic targeting.
Stated Motivations
The group has presented its activity as support for Palestine and retaliation against Israel and governments that maintain political or military relationships with Israel.
In a November 2024 statement, 313 Team listed Israel, NATO members, countries supporting Israel, Gulf governments (Bahrain, Kuwait, Qatar, Saudi Arabia, and the United Arab Emirates), Jordan, and Egypt among its intended targets. The same statement expressed support for Iran, the Islamic Revolutionary Guard Corps, Hezbollah, Ansar Allah, the former Syrian government under Bashar al-Assad, and Russia.

Later statements continued to link the group’s attacks to regional political and military events. In July 2026, 313 Team said its attack against Saudi Arabia’s Nafath digital identity platform was retaliation for reported airstrikes on Sana’a International Airport.


Based on the group’s statements and the explanations it gives for selected attacks, its stated or apparent motivations include:
Support for Palestine and opposition to organizations and governments it considers supportive of Israel.
Support for Iran and several Iran-aligned regional actors, including the Islamic Revolutionary Guard Corps, Hezbollah, and Ansar Allah.
Retaliation for military or political actions involving Iran, Yemen, Palestine, or groups aligned with the broader Axis of Resistance.
Opposition to Israel, the United States, NATO members, and the governments of Saudi Arabia, the United Arab Emirates, Kuwait, Qatar, Bahrain, Jordan, and Egypt when the group considers their policies hostile to its stated causes.
Opposition to countries or organizations it accuses of insulting Islam or Muslims.
Shia religious references and support for the regional resistance movement.
These motivations are based primarily on the group's own public statements. They do not establish formal control, sponsorship, or direction by Iran or another government.
Ideology and Actual Targeting
The group's stated ideology only partially explains its target selection.
Some claimed operations align directly with its political messaging. These include attacks against Israeli organizations, U.S. government services, Saudi government infrastructure, military-related financial institutions, and organizations linked by the group to political events in the Middle East.
However, other targets appear to have little direct connection to the group's stated cause. Examples include:
Spotify
Reddit
Yelp
Scratch
Moodle
Strava
Squarespace
Whatnot
eBay
LinkedIn
Shopify
Disney+
OpenAI
Proton
Waze
The group has also targeted widely used infrastructure and service providers, including Cloudflare, GoDaddy, Ubuntu, Microsoft, Everbridge, and the U.S. National Weather Service.
This broader pattern suggests that ideology may not be the only factor driving target selection. Visibility, brand recognition, reliance on public-facing services, and the likelihood of generating measurable outage reports also appear to influence which organizations are selected.
Operational Activity
313 Team's most consistent activity is DDoS attacks. The group typically announces a target, identifies a specific URL or service endpoint, and states an intended attack duration. It then issues updates claiming that the attack has been extended, intensified, mitigated, or completed.
Commonly targeted endpoints include:
Login portals
Public websites
Mobile applications
APIs
Streaming services
Emergency communications platforms
Login services appear repeatedly in the group's claims. Targeting authentication interfaces can prevent users from accessing an otherwise functioning platform and may create a visible operational impact without requiring access to the target's internal network.
Tools and Attack Services
313 Team appears to rely on DDoS capabilities developed and operated by other groups. Services used or promoted by 313 Team in connection with its attacks include:
Beamed
EliteStress
Cypher
This operating model lowers the technical barrier required to conduct sustained DDoS activity. Rather than maintaining a proprietary botnet or attack platform, the group can purchase or obtain access to commercial DDoS infrastructure and direct it at selected endpoints.
Monitoring 313 Team in VenariX
VenariX tracks 313 Team, reviews its activity, and records incidents attributed to the group. Each claim is analyzed against external reporting, service status information, affected-organization statements, and other available evidence to determine whether the incident can be confirmed.
Of the incidents attributed to 313 Team and recorded in VenariX, 72% have been independently confirmed. This gives users a measurable basis for evaluating the group’s credibility and separating substantiated activity from unsupported claims.
The 313 Team profile brings together:
Confirmed and unverified incidents
Targeted organizations, countries, sectors, industries, and other demographics.
Attack types and operational patterns
Supporting evidence and public references
Campaigns and related threat actors
Changes in activity and targeting over time
Users can also create alerts to receive updates when new incidents associated with 313 Team are added to VenariX.