From Steel to Crypto: The Evolving Tactics of Predatory Sparrow

From Steel to Crypto: The Evolving Tactics of Predatory Sparrow
  • calendar_today September 3, 2025
  • Technology

This week, Iran’s financial systems were in chaos after a string of catastrophic cyberattacks from Predatory Sparrow, a hacker group thought to be connected to Israeli intelligence.

On Wednesday, the group aimed at Sepah Bank, a major financial institution connected to Iran’s elite military forces, and Nobitex, the biggest cryptocurrency exchange in the nation. By doing so, Predatory Sparrow sent a strong and unambiguous message: Iran’s digital economy is no longer safe.

The attack on Nobitex deviated from the accepted cyber theft playbook. Blockchain tracing company Elliptic claims that hackers purposefully destroyed more than $90 million in cryptocurrency, forwarding it to “vanity” wallet addresses bearing words like “FuckIRGCterrorists.” There is no recovery from these addresses. Once the crypto reaches them, it’s gone forever.

“This was never about stealing,” Elliptic co-founder Tom Robinson said. “The attackers purposefully selected a technique meant to wipe the money out of existence. That is not theft—that is sabotage.

Predatory Sparrow claimed in a post on X that Nobitex was running as a financial conduit for terrorism funding and sanctions avoidance. They asserted the platform handled payments for groups including Hamas, the Houthis, Palestinian Islamic Jihad, and wallets connected to the IRGC.

Elliptic verified that Nobitex was indeed receiving payments from wallets linked to approved groups.

Nobitex went dark and its website vanished shortly after the hack was reported. There has been no public comment or user guidance given; simply silence.

That was only one blow, though.

Predatory Sparrow later that same day turned its digital weapon toward Sepah Bank. Claiming to be working with the Islamic Revolutionary Guard Corps, the group said they had deleted all internal data and leaked papers implying Sepah was financially supporting Iran’s nuclear and missile projects.

Their admonition was direct: “Caution: Working with approved governments could cost you everything.” Who’s next?

The results were quick and broad. Based in Sweden, cybersecurity researcher Hamid Kashfi said he heard from Iran that ATM services and online banking connected to Sepah Bank had gone off-target. Cash withdrawal was not possible for people. A few couldn’t even log into their accounts. This touched actual people, not only institutions, Kashfi said.

Sepah’s main website briefly came back, but the situation of her internal systems is not clear-cut. The Iranian government is not yet commenting.

Considered among the most dangerous cyber actors in the area, Predatory Sparrow has previously attacked Iran’s fuel network, railroads, and even an industrial steel mill. The group has used a sabotage operation to cause molten metal to spill and set flames on the factory floor.

Most cybersecurity experts agree that, despite their claims to be a domestic Iranian resistance movement under the name Gonjeshke Darande, they most certainly represent Israeli intelligence operations.

John Hultquist, a threat analyst for Google’s Mandiant team, said: “This is a serious, state-grade threat actor.” “Predatory Sparrow blends bold message, accuracy, and intelligence. It is cyberwarfare with a PR approach.

Striking Nobitex was about undercutting Iran’s attempt to use cryptocurrencies to evade U.S. and EU sanctions, not only about digital money. Conversely, Sepah Bank is absolutely essential for funding Iran’s nuclear aspirations and state military projects.

Predatory Sparrow tore both with one hit.

It remains to be seen if this most recent campaign is a warning, an escalation, or a component of a more general plan. The last words in the group’s post, however, imply more to come.

And if their record is accurate, Iran and the world should pay close attention.