313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against E-Commerce APIs (CVE-2025-39391) — Threadlinqs Intelligence
As of 2026-07-15, 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against E-Commerce APIs (CVE-2025-39391) is a high-severity threat intel threat attributed to 313 Team (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1374 · Severity: HIGH · CVSS: 7.5 · Status: ACTIVE · Category: THREAT_INTEL
Attribution: 313 Team · Iran · HACKTIVISM
Akamai's July 2026 "Smash and Grab at Scale" report documents 313 Team, an Iran-aligned hacktivist collective, combining Mirai-derived IoT botnets, browser impersonation, and Layer 7 DDoS against
313 Team (also tracked as 313 Team Hack Team / Islamic Cyber Resistance, with claimed convergence to Void Manticore, Storm-0842, and BANISHED KITTEN in some vendor reporting) is an Iran-aligned hacktivist collective assessed to operate with Iranian Ministry of Intelligence and Security (MOIS) / IRGC alignment, active since December 2023 in the context of the Gaza conflict and broader Iran-Israel/US shadow war. The group's core capability set is volumetric and application-layer DDoS -- delivered through Mirai-derived IoT botnets pooled with the wider Islamic Cyber Resistance coalition (RipperSec, FAD Team/Fatimiyoun Cyber Team, Cyb3rDrag0nzz, Moroccan Black Cyber Army, Holy League, Tharulla Brigade, Conquer Electronic Army, SEPAHCYBERY) -- combined with browser impersonation to evade bot-mitigation controls on e-commerce and government API endpoints.
Akamai's telemetry places this activity inside a broader 2025-2026 surge: nearly 3 trillion Layer 7 DDoS attacks recorded in 2025, 84% of which targeted retail, 31% targeting APIs specifically, a 19% YoY increase in AI-driven bot traffic (retail-dominated), 200+ billion application/API attacks against commerce in 2024-2025, a 9% YoY increase in API attacks (Q4 2024-Q4 2025), and a 39% YoY increase in Asia-Pacific Layer 7 DDoS. Documented 313 Team/coalition operations include an 18-hour outage of the Kuwait e-Government portal, a 72+ hour sustained campaign against 26 Kuwaiti government domains, a 72+ hour campaign against Saudi Arabia's Absher platform, a DDoS against Truth Social within ~20 minutes of a Trump social-media post, a claimed 5+ hour DDoS against Microsoft 365, and a sustained attack on Canonical/Ubuntu web infrastructure.
The campaign has escalated beyond DDoS/defacement into destructive operations: a March 2026 attack against a medical-technology company (internally referred to in reporting as "313 Team Corp") deployed an NSIS-packaged wiper that overwrote files with random 4,096-byte chunks, exploited a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique via an AutoIt3.exe-launched .a3x script invoking RtlDecompressFragment() and a kernel driver (ListOpenedFileDrv) for file enumeration, abused Microsoft Intune MDM to remotely wipe 200,000+ managed endpoints, defaced Microsoft Entra login portals, and exfiltrated system information to a Telegram-bot C2 channel before destruction. Primary and coalition tooling includes the HackBar browser-based SQLi/XSS audit tool, CheckHost.net for outage-proof screenshots posted to Telegram, and Storj/Mega for payload and leak-data hosting.
Akamai's report documents new AI-native TTPs directly affecting production commerce platforms: (1) "leaky faucet" attacks, in which automated logic exploits methodically manipulate chatbot input parameters to override retailer business rules (pricing, discounting, inventory holds); (2) prompt injection and jailbreak techniques against back-end conversational AI agents that hold deep operational authority (order modification, refunds, account actions); and (3) AI token freeloading, where threat actors route their own inference or model-training workloads through a retailer's public-facing AI endpoints, driving unauthorized infrastructure cost (a resource-hijacking pattern against LLM compute rather than traditional CPU/GPU mining). Separately, the report names an actively exploited WordPress vulnerability affecting the retail stack: CVE-2025-39391, a Local File Inclusion (LFI) flaw (CWE-98: Improper Control of Filename for Include/Require Statement in PHP) in the "Checkout Field Visibility for WooCommerce" plugin (versions through 1.3.0), allowing unauthenticated-adjacent path manipulation of PHP include()/require() calls to disclose wp-config.php and other sensitive server-side files (CVSS 3.1: 7.5 HIGH, AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). No vendor patch was available for CFV-WooCommerce at time of reporting. Akamai's report separately references the unrelated Jupiter X Core WooCommerce/Word
Target sectors: retail, ecommerce, government administration, finance, banking, telecoms, technology, health
Target regions: Middle East, Gulf Cooperation Council, North America, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, CVE-2025-39391, T1583.005, T1595, T1190, T1566.002, T1059, T1068, T1215, T1113, T1071.001, T1102.002