CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Ababil of Minab

actor · actor:ababil-of-minab-mois-attribution-lacmta-march-2026-700gb-backups-destroyed

Hacktivist front attributed to Iran's MOIS, responsible for the March 2026 destructive breach of LA Metro (LACMTA): 700 GB exfiltrated, VMs and backups deliberately destroyed.

Coverage
1
first 2026-05-28 → last 2026-05-28
Latest activity
2026-05-28
Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front, 700 GB exfiltrated…
Peak priority
notable
1 notable
Targets
transport
sectors: transport, public-sector · regions: us, middle-east
Sources cited
3
3 hosts

Defender insights

What each entry about Ababil of Minab tells a defender to do, newest first.

2026-05-28NOTABLEIran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front, 700 GB exfiltrated, backups and VMs deliberately destroyed

Story timeline

  1. 2026-05-28Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front, 700 GB exfiltrated, backups and VMs deliberately destroyed
    active-threats
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactData Destruction

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-05-28/iran-mois-attributed-to-lacmta-destructive-breach-via-ababil · ATT&CK page ↗

Entries about Ababil of Minab (1)

2026-05-28 · view entry permalink →

NOTABLE

Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front, 700 GB exfiltrated, backups and VMs deliberately destroyed

Gambit Security (Israeli threat-intelligence firm) published a technical report on 2026-05-26 attributing the March 2026 breach of Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro) to an Iran-MOIS-linked cluster operating under the hacktivist persona Ababil of Minab (Gambit Security, 2026-05-26; TechCrunch, 2026-05-26; The Record, 2026-05-27). The persona surfaced in late March / early April 2026 claiming to be a standalone hacktivist crew; Gambit's forensic evidence ties the cluster's infrastructure and techniques to the MOIS-attributed Black Shadow group, a designation the Israel National Cyber Directorate (INCD) has previously applied. The campaign exfiltrated a large volume of emails, backups and other files from LACMTA, then deliberately targeted the recovery layer: virtual machines and storage volumes were deleted, backup infrastructure was destroyed, and multiple destructive techniques were applied in parallel to force concurrent remediation pathways and maximise downtime. LA Metro required weeks to recover. The campaign also touched named and unnamed organisations in Israel, Saudi Arabia and Turkey.

threat28 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • gambit.security1 (33%)
  • techcrunch.com1 (33%)
  • therecord.media1 (33%)