313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against E-Commerce APIs (CVE-2025-39391)

313 Team Iran-Aligned Hacktivists Weaponize Agentic AI (TL-2026-1374), also tracked as Smash and Grab at Scale Campaign, is a high-severity tracked intrusion set scored CVSS 7.5, first published 2026-07-15. It is attributed to 313 Team (Iran) with medium confidence, affects zamartz Checkout Field Visibility for WooCommerce (WordPress plugin), references 1 CVE (CVE-2025-39391), maps to 18 MITRE ATT&CK techniques (T1059, T1068, T1071.001), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-1374

Threat ID
TL-2026-1374
Also known as
Smash and Grab at Scale Campaign, Islamic Cyber Resistance Axis
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-15
Last reviewed
2026-07-15
Attribution
313 Team
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
HACKTIVISM
Target sectors
retail, ecommerce, government administration, finance, banking, telecoms, technology, health
Target regions
Middle East, Gulf Cooperation Council, North America, Asia-Pacific
Detection rules
9
Indicators of compromise
25

Malware and tooling in 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

Malware and tooling: 313 Team NSIS Wiper, CheckHost.net, HackBar, ListOpenedFileDrv, Telegram

Akamai's July 2026 "Smash and Grab at Scale" report documents 313 Team, an Iran-aligned hacktivist collective, combining Mirai-derived IoT botnets, browser impersonation, and Layer 7 DDoS against e-commerce APIs alongside emerging AI-native attack techniques -- chatbot "leaky faucet" logic exploitation, prompt injection/jailbreaks against back-end conversational AI agents, and unauthorized AI token freeloading -- and actively exploiting the WooCommerce Checkout Field Visibility plugin LFI flaw CVE-2025-39391.

How 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI works

313 Team (also tracked as 313 Team Hack Team / Islamic Cyber Resistance, with claimed convergence to Void Manticore, Storm-0842, and BANISHED KITTEN in some vendor reporting) is an Iran-aligned hacktivist collective assessed to operate with Iranian Ministry of Intelligence and Security (MOIS) / IRGC alignment, active since December 2023 in the context of the Gaza conflict and broader Iran-Israel/US shadow war. The group's core capability set is volumetric and application-layer DDoS -- delivered through Mirai-derived IoT botnets pooled with the wider Islamic Cyber Resistance coalition (RipperSec, FAD Team/Fatimiyoun Cyber Team, Cyb3rDrag0nzz, Moroccan Black Cyber Army, Holy League, Tharulla Brigade, Conquer Electronic Army, SEPAHCYBERY) -- combined with browser impersonation to evade bot-mitigation controls on e-commerce and government API endpoints.

Akamai's telemetry places this activity inside a broader 2025-2026 surge: nearly 3 trillion Layer 7 DDoS attacks recorded in 2025, 84% of which targeted retail, 31% targeting APIs specifically, a 19% YoY increase in AI-driven bot traffic (retail-dominated), 200+ billion application/API attacks against commerce in 2024-2025, a 9% YoY increase in API attacks (Q4 2024-Q4 2025), and a 39% YoY increase in Asia-Pacific Layer 7 DDoS. Documented 313 Team/coalition operations include an 18-hour outage of the Kuwait e-Government portal, a 72+ hour sustained campaign against 26 Kuwaiti government domains, a 72+ hour campaign against Saudi Arabia's Absher platform, a DDoS against Truth Social within ~20 minutes of a Trump social-media post, a claimed 5+ hour DDoS against Microsoft 365, and a sustained attack on Canonical/Ubuntu web infrastructure.

The campaign has escalated beyond DDoS/defacement into destructive operations: a March 2026 attack against a medical-technology company (internally referred to in reporting as "313 Team Corp") deployed an NSIS-packaged wiper that overwrote files with random 4,096-byte chunks, exploited a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique via an AutoIt3.exe-launched .a3x script invoking RtlDecompressFragment() and a kernel driver (ListOpenedFileDrv) for file enumeration, abused Microsoft Intune MDM to remotely wipe 200,000+ managed endpoints, defaced Microsoft Entra login portals, and exfiltrated system information to a Telegram-bot C2 channel before destruction. Primary and coalition tooling includes the HackBar browser-based SQLi/XSS audit tool, CheckHost.net for outage-proof screenshots posted to Telegram, and Storj/Mega for payload and leak-data hosting.

Akamai's report documents new AI-native TTPs directly affecting production commerce platforms: (1) "leaky faucet" attacks, in which automated logic exploits methodically manipulate chatbot input parameters to override retailer business rules (pricing, discounting, inventory holds); (2) prompt injection and jailbreak techniques against back-end conversational AI agents that hold deep operational authority (order modification, refunds, account actions); and (3) AI token freeloading, where threat actors route their own inference or model-training workloads through a retailer's public-facing AI endpoints, driving unauthorized infrastructure cost (a resource-hijacking pattern against LLM compute rather than traditional CPU/GPU mining). Separately, the report names an actively exploited WordPress vulnerability affecting the retail stack: CVE-2025-39391, a Local File Inclusion (LFI) flaw (CWE-98: Improper Control of Filename for Include/Require Statement in PHP) in the "Checkout Field Visibility for WooCommerce" plugin (versions through 1.3.0), allowing unauthenticated-adjacent path manipulation of PHP include()/require() calls to disclose wp-config.php and other sensitive server-side files (CVSS 3.1: 7.5 HIGH, AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). No vendor patch was available for CFV-WooCommerce at time of reporting. Akamai's report separately references the unrelated Jupiter X Core WooCommerce/WordPress theme plugin (172,000+ installs; historically affected by unauthenticated file-upload RCE CVE-2023-38388 and account-takeover CVE-2023-38389, both patched in v3.4.3) as an example of the broader plugin attack surface facing e-commerce operators, without confirming 313 Team exploitation of those specific CVEs.

Multi-vendor sourcing (Microsoft, CrowdStrike, Check Point Research, Cisco Talos referenced in coalition threat-advisory reporting) assesses the group's operational doctrine as visibility-over-damage: Telegram amplification (250,000+ coalition messages during the June 2025 conflict cycle), proof screenshots, and psychological/influence-operations impact take priority over sustained monetization, though the March 2026 wiper incident marks a qualitative shift toward permanent data destruction against critical infrastructure and healthcare-adjacent targets. Analysts caution that actor self-reported claims (CCTV access to Bahraini facilities, ICS/OT access to Gulf infrastructure) are collection leads, not independently confirmed compromises.

MITRE ATT&CK techniques used in TL-2026-1374

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication

Collection

T1113 Screen Capture

Initial Access

T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link

Impact

T1485 Data Destruction; T1491.002 External Defacement; T1496 Resource Hijacking; T1498.001 Direct Network Flood; T1499.004 Application or System Exploitation; T1561.001 Disk Content Wipe; T1565.001 Stored Data Manipulation

Persistence

T1547.006 Kernel Modules and Extensions

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Resource Development

T1583.005 Botnet

Reconnaissance

T1595 Active Scanning

Affected products and versions in 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

  • zamartz — Checkout Field Visibility for WooCommerce (WordPress plugin)
    Vulnerable versions: <= 1.3.0
  • Artbees — Jupiter X Core (WordPress/WooCommerce theme plugin)
    Vulnerable versions: < 3.4.3
    Fixed in: 3.4.3
  • Multiple e-commerce platforms — Back-end conversational AI agents / chatbots with operational authority (order, refund, discount actions)
    Vulnerable versions: N/A - logic/architecture flaw, not versioned

Remediation for 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

Patches

  • No vendor patch available for Checkout Field Visibility for WooCommerce as of reporting -- monitor Patchstack/WordPress.org for a fixed release beyond 1.3.0
  • Jupiter X Core: upgrade to v3.4.3+ to remediate unrelated CVE-2023-38388 and CVE-2023-38389 (unauthenticated file upload RCE and account takeover)

Immediate actions

  • Deactivate or restrict the Checkout Field Visibility for WooCommerce plugin (versions through 1.3.0) until a vendor patch for CVE-2025-39391 is released
  • Deploy WAF/CDN rules blocking path-traversal patterns in filename/include parameters on WordPress/WooCommerce checkout endpoints
  • Rate-limit and behaviorally fingerprint AI chatbot and conversational-agent endpoints to detect systematic business-rule-override probing (leaky faucet patterns)
  • Restrict back-end AI agent tool permissions (order modification, refunds, discounting) behind explicit human-approval gates, not model-inferred authorization
  • Meter and authenticate access to public-facing AI/LLM inference endpoints to prevent token-freeloading resource hijacking
  • Apply Layer 7 / API-aware DDoS mitigation and bot-management controls tuned for browser-impersonation traffic on e-commerce APIs

Workarounds

  • Temporarily deactivate the Checkout Field Visibility for WooCommerce plugin
  • Restrict filesystem read scope for the PHP process/web server user to prevent wp-config.php disclosure via LFI

Longer-term hardening

  • Adopt continuous vulnerability scanning of third-party WordPress/WooCommerce plugin inventory with SLA-based patch enforcement
  • Implement prompt-injection detection/guardrails and output validation for all customer-facing and back-end LLM agents
  • Segment and restrict Microsoft Intune/MDM administrative scope to prevent mass remote-wipe abuse; enforce break-glass approval for bulk device actions
  • Deploy BYOVD-aware EDR/driver allow-listing to block loading of vulnerable signed kernel drivers
  • Establish DDoS/hacktivist surge playbooks tied to geopolitical trigger events (Iran-Israel/US escalation cycles)

CVEs associated with 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

CVE-2025-39391

Weaknesses (CWE) in 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

CWE-98

Timeline of 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

  • 313 Team / Islamic Cyber Resistance coalition emerges amid the Gaza conflict, adopting its name from a 1969 Palestinian political symbol and beginning sustained DDoS campaigns against Saudi Arabia's Absher government platform.
  • CVE-2025-39391, a Local File Inclusion vulnerability in the Checkout Field Visibility for WooCommerce plugin (through v1.3.0), is publicly disclosed.
  • 313 Team and coalition partners (Hamza, Keymous+, Cyber Jihad) launch coordinated DDoS against US military, defense, financial, and political targets following US airstrikes on Iranian nuclear sites; Truth Social is hit within ~20 minutes of a Trump social media post.
  • GBHackers reports pro-Iran hacktivist coalitions, including 313 Team-aligned groups, launching coordinated DDoS and hack-and-leak attacks against critical infrastructure across multiple countries.
  • DailyDarkWeb publishes an exclusive interview with 313 Team representatives detailing the group's motivations, coalition ties, and operational claims.
  • 313 Team publicly threatens 'severe cyberattacks' against Saudi Arabia.
  • 313 Team conducts a sustained 72+ hour DDoS operation against 26 Kuwaiti government domains, including an 18-hour outage of the Kuwait e-Government portal.
  • TheHackerNews reports 149 hacktivist DDoS attacks against 110 organizations across 16 countries in the wake of Middle East conflict escalation, consistent with the Islamic Cyber Resistance coalition's operational tempo.
  • 313 Team deploys an NSIS-packaged, BYOVD-enabled wiper against a medical technology company, destructively wiping 200,000+ Microsoft Intune-managed devices and defacing Microsoft Entra login portals -- a qualitative shift from DDoS/defacement to destructive attack.
  • Akamai publishes 'Smash and Grab at Scale,' documenting 313 Team's agentic-AI-driven attacks on e-commerce APIs, active exploitation of CVE-2025-39391, and emerging AI-native TTPs (leaky faucet chatbot abuse, prompt injection/jailbreaks, AI token freeloading).

Sources cited for 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

Threats related to 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI

Detection coverage for TL-2026-1374

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1374 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats