ctipilot.ch

Ababil of Minab

actor · actor:ababil-of-minab-mois-attribution-lacmta-march-2026-700gb-backups-destroyed

Hacktivist front attributed to Iran's MOIS, responsible for the March 2026 destructive breach of LA Metro (LACMTA): 700 GB exfiltrated, VMs and backups deliberately destroyed.

Coverage timeline
2
first 2026-05-25 → last 2026-05-28
Peak priority
notable
2 notable
Sources cited
3
3 hosts
Sections touched
2
active-threats, weekly-sector-patterns
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below
2026-05-252 appearances2026-05-28

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-05-28/iran-mois-attributed-to-lacmta-destructive-breach-via-ababil · ATT&CK page ↗

Story timeline

  1. 2026-05-28Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front — 700 GB exfiltrated, backups and VMs deliberately destroyed
    active-threats
  2. 2026-05-25Transport — Iran-MOIS destructive breach against LACMTA with deliberate backup and VM destruction
    weekly-sector-patterns

Where this entity is cited

  • weekly-sector-patterns1
  • active-threats1

Source distribution

  • gambit.security1 (33%)
  • techcrunch.com1 (33%)
  • therecord.media1 (33%)

explore in graph

Entries about Ababil of Minab (2)

2026-05-28 · view entry permalink →

NOTABLE

Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front — 700 GB exfiltrated, backups and VMs deliberately destroyed

Gambit Security (Israeli threat-intelligence firm) published a technical report on 2026-05-26 attributing the March 2026 breach of Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro) to an Iran-MOIS-linked cluster operating under the hacktivist persona Ababil of Minab (Gambit Security, 2026-05-26; TechCrunch, 2026-05-26; The Record, 2026-05-27). The persona surfaced in late March / early April 2026 claiming to be a standalone hacktivist crew; Gambit's forensic evidence ties the cluster's infrastructure and techniques to the MOIS-attributed Black Shadow group, a designation the Israel National Cyber Directorate (INCD) has previously applied. The campaign exfiltrated a large volume of emails, backups and other files from LACMTA, then deliberately targeted the recovery layer: virtual machines and storage volumes were deleted, backup infrastructure was destroyed, and multiple destructive techniques were applied in parallel to force concurrent remediation pathways and maximise downtime. LA Metro required weeks to recover. The campaign also touched named and unnamed organisations in Israel, Saudi Arabia and Turkey.

threat28 May 05:00Zmulti-sourceOpen finding ↗

2026-05-25 · view entry permalink →

NOTABLE

Transport — Iran-MOIS destructive breach against LACMTA with deliberate backup and VM destruction

The window's standout transport-sector event was destructive, not extortive. Gambit Security attributed the LACMTA (Los Angeles Metro) breach to Iran's MOIS operating behind the "Ababil of Minab" hacktivist front, with ~700 GB exfiltrated and backups and virtual machines deliberately destroyed (2026-05-28). The relevance for European public-transit and public-sector defenders is the recovery-planning implication: where the adversary's objective is destruction rather than ransom, restoration assumes offline / immutable backups and rebuild-from-known-good capacity — controls that an extortion-only threat model under-provisions. The "hacktivist front for state destruction" pattern also complicates attribution and the public-comms response.

synthesis25 May 05:00Zmulti-sourceOpen finding ↗