313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against E-Commerce APIs (CVE-2025-39391)
313 Team Iran-Aligned Hacktivists Weaponize Agentic AI (TL-2026-1374), also tracked as Smash and Grab at Scale Campaign, is a high-severity tracked intrusion set scored CVSS 7.5, first published 2026-07-15. It is attributed to 313 Team (Iran) with medium confidence, affects zamartz Checkout Field Visibility for WooCommerce (WordPress plugin), references 1 CVE (CVE-2025-39391), maps to 18 MITRE ATT&CK techniques (T1059, T1068, T1071.001), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-1374
- Threat ID
- TL-2026-1374
- Also known as
- Smash and Grab at Scale Campaign, Islamic Cyber Resistance Axis
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution
- 313 Team
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- HACKTIVISM
- Target sectors
- retail, ecommerce, government administration, finance, banking, telecoms, technology, health
- Target regions
- Middle East, Gulf Cooperation Council, North America, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
Malware and tooling: 313 Team NSIS Wiper, CheckHost.net, HackBar, ListOpenedFileDrv, Telegram
Akamai's July 2026 "Smash and Grab at Scale" report documents 313 Team, an Iran-aligned hacktivist collective, combining Mirai-derived IoT botnets, browser impersonation, and Layer 7 DDoS against e-commerce APIs alongside emerging AI-native attack techniques -- chatbot "leaky faucet" logic exploitation, prompt injection/jailbreaks against back-end conversational AI agents, and unauthorized AI token freeloading -- and actively exploiting the WooCommerce Checkout Field Visibility plugin LFI flaw CVE-2025-39391.
How 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI works
313 Team (also tracked as 313 Team Hack Team / Islamic Cyber Resistance, with claimed convergence to Void Manticore, Storm-0842, and BANISHED KITTEN in some vendor reporting) is an Iran-aligned hacktivist collective assessed to operate with Iranian Ministry of Intelligence and Security (MOIS) / IRGC alignment, active since December 2023 in the context of the Gaza conflict and broader Iran-Israel/US shadow war. The group's core capability set is volumetric and application-layer DDoS -- delivered through Mirai-derived IoT botnets pooled with the wider Islamic Cyber Resistance coalition (RipperSec, FAD Team/Fatimiyoun Cyber Team, Cyb3rDrag0nzz, Moroccan Black Cyber Army, Holy League, Tharulla Brigade, Conquer Electronic Army, SEPAHCYBERY) -- combined with browser impersonation to evade bot-mitigation controls on e-commerce and government API endpoints.
Akamai's telemetry places this activity inside a broader 2025-2026 surge: nearly 3 trillion Layer 7 DDoS attacks recorded in 2025, 84% of which targeted retail, 31% targeting APIs specifically, a 19% YoY increase in AI-driven bot traffic (retail-dominated), 200+ billion application/API attacks against commerce in 2024-2025, a 9% YoY increase in API attacks (Q4 2024-Q4 2025), and a 39% YoY increase in Asia-Pacific Layer 7 DDoS. Documented 313 Team/coalition operations include an 18-hour outage of the Kuwait e-Government portal, a 72+ hour sustained campaign against 26 Kuwaiti government domains, a 72+ hour campaign against Saudi Arabia's Absher platform, a DDoS against Truth Social within ~20 minutes of a Trump social-media post, a claimed 5+ hour DDoS against Microsoft 365, and a sustained attack on Canonical/Ubuntu web infrastructure.
The campaign has escalated beyond DDoS/defacement into destructive operations: a March 2026 attack against a medical-technology company (internally referred to in reporting as "313 Team Corp") deployed an NSIS-packaged wiper that overwrote files with random 4,096-byte chunks, exploited a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique via an AutoIt3.exe-launched .a3x script invoking RtlDecompressFragment() and a kernel driver (ListOpenedFileDrv) for file enumeration, abused Microsoft Intune MDM to remotely wipe 200,000+ managed endpoints, defaced Microsoft Entra login portals, and exfiltrated system information to a Telegram-bot C2 channel before destruction. Primary and coalition tooling includes the HackBar browser-based SQLi/XSS audit tool, CheckHost.net for outage-proof screenshots posted to Telegram, and Storj/Mega for payload and leak-data hosting.
Akamai's report documents new AI-native TTPs directly affecting production commerce platforms: (1) "leaky faucet" attacks, in which automated logic exploits methodically manipulate chatbot input parameters to override retailer business rules (pricing, discounting, inventory holds); (2) prompt injection and jailbreak techniques against back-end conversational AI agents that hold deep operational authority (order modification, refunds, account actions); and (3) AI token freeloading, where threat actors route their own inference or model-training workloads through a retailer's public-facing AI endpoints, driving unauthorized infrastructure cost (a resource-hijacking pattern against LLM compute rather than traditional CPU/GPU mining). Separately, the report names an actively exploited WordPress vulnerability affecting the retail stack: CVE-2025-39391, a Local File Inclusion (LFI) flaw (CWE-98: Improper Control of Filename for Include/Require Statement in PHP) in the "Checkout Field Visibility for WooCommerce" plugin (versions through 1.3.0), allowing unauthenticated-adjacent path manipulation of PHP include()/require() calls to disclose wp-config.php and other sensitive server-side files (CVSS 3.1: 7.5 HIGH, AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). No vendor patch was available for CFV-WooCommerce at time of reporting. Akamai's report separately references the unrelated Jupiter X Core WooCommerce/WordPress theme plugin (172,000+ installs; historically affected by unauthenticated file-upload RCE CVE-2023-38388 and account-takeover CVE-2023-38389, both patched in v3.4.3) as an example of the broader plugin attack surface facing e-commerce operators, without confirming 313 Team exploitation of those specific CVEs.
Multi-vendor sourcing (Microsoft, CrowdStrike, Check Point Research, Cisco Talos referenced in coalition threat-advisory reporting) assesses the group's operational doctrine as visibility-over-damage: Telegram amplification (250,000+ coalition messages during the June 2025 conflict cycle), proof screenshots, and psychological/influence-operations impact take priority over sustained monetization, though the March 2026 wiper incident marks a qualitative shift toward permanent data destruction against critical infrastructure and healthcare-adjacent targets. Analysts caution that actor self-reported claims (CCTV access to Bahraini facilities, ICS/OT access to Gulf infrastructure) are collection leads, not independently confirmed compromises.
MITRE ATT&CK techniques used in TL-2026-1374
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication
Collection
Initial Access
T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link
Impact
T1485 Data Destruction; T1491.002 External Defacement; T1496 Resource Hijacking; T1498.001 Direct Network Flood; T1499.004 Application or System Exploitation; T1561.001 Disk Content Wipe; T1565.001 Stored Data Manipulation
Persistence
T1547.006 Kernel Modules and Extensions
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Resource Development
Reconnaissance
Affected products and versions in 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
- zamartz — Checkout Field Visibility for WooCommerce (WordPress plugin)
Vulnerable versions: <= 1.3.0 - Artbees — Jupiter X Core (WordPress/WooCommerce theme plugin)
Vulnerable versions: < 3.4.3
Fixed in: 3.4.3 - Multiple e-commerce platforms — Back-end conversational AI agents / chatbots with operational authority (order, refund, discount actions)
Vulnerable versions: N/A - logic/architecture flaw, not versioned
Remediation for 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
Patches
- No vendor patch available for Checkout Field Visibility for WooCommerce as of reporting -- monitor Patchstack/WordPress.org for a fixed release beyond 1.3.0
- Jupiter X Core: upgrade to v3.4.3+ to remediate unrelated CVE-2023-38388 and CVE-2023-38389 (unauthenticated file upload RCE and account takeover)
Immediate actions
- Deactivate or restrict the Checkout Field Visibility for WooCommerce plugin (versions through 1.3.0) until a vendor patch for CVE-2025-39391 is released
- Deploy WAF/CDN rules blocking path-traversal patterns in filename/include parameters on WordPress/WooCommerce checkout endpoints
- Rate-limit and behaviorally fingerprint AI chatbot and conversational-agent endpoints to detect systematic business-rule-override probing (leaky faucet patterns)
- Restrict back-end AI agent tool permissions (order modification, refunds, discounting) behind explicit human-approval gates, not model-inferred authorization
- Meter and authenticate access to public-facing AI/LLM inference endpoints to prevent token-freeloading resource hijacking
- Apply Layer 7 / API-aware DDoS mitigation and bot-management controls tuned for browser-impersonation traffic on e-commerce APIs
Workarounds
- Temporarily deactivate the Checkout Field Visibility for WooCommerce plugin
- Restrict filesystem read scope for the PHP process/web server user to prevent wp-config.php disclosure via LFI
Longer-term hardening
- Adopt continuous vulnerability scanning of third-party WordPress/WooCommerce plugin inventory with SLA-based patch enforcement
- Implement prompt-injection detection/guardrails and output validation for all customer-facing and back-end LLM agents
- Segment and restrict Microsoft Intune/MDM administrative scope to prevent mass remote-wipe abuse; enforce break-glass approval for bulk device actions
- Deploy BYOVD-aware EDR/driver allow-listing to block loading of vulnerable signed kernel drivers
- Establish DDoS/hacktivist surge playbooks tied to geopolitical trigger events (Iran-Israel/US escalation cycles)
CVEs associated with 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
Weaknesses (CWE) in 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
CWE-98
Timeline of 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
- 313 Team / Islamic Cyber Resistance coalition emerges amid the Gaza conflict, adopting its name from a 1969 Palestinian political symbol and beginning sustained DDoS campaigns against Saudi Arabia's Absher government platform.
- CVE-2025-39391, a Local File Inclusion vulnerability in the Checkout Field Visibility for WooCommerce plugin (through v1.3.0), is publicly disclosed.
- 313 Team and coalition partners (Hamza, Keymous+, Cyber Jihad) launch coordinated DDoS against US military, defense, financial, and political targets following US airstrikes on Iranian nuclear sites; Truth Social is hit within ~20 minutes of a Trump social media post.
- GBHackers reports pro-Iran hacktivist coalitions, including 313 Team-aligned groups, launching coordinated DDoS and hack-and-leak attacks against critical infrastructure across multiple countries.
- DailyDarkWeb publishes an exclusive interview with 313 Team representatives detailing the group's motivations, coalition ties, and operational claims.
- 313 Team publicly threatens 'severe cyberattacks' against Saudi Arabia.
- 313 Team conducts a sustained 72+ hour DDoS operation against 26 Kuwaiti government domains, including an 18-hour outage of the Kuwait e-Government portal.
- TheHackerNews reports 149 hacktivist DDoS attacks against 110 organizations across 16 countries in the wake of Middle East conflict escalation, consistent with the Islamic Cyber Resistance coalition's operational tempo.
- 313 Team deploys an NSIS-packaged, BYOVD-enabled wiper against a medical technology company, destructively wiping 200,000+ Microsoft Intune-managed devices and defacing Microsoft Entra login portals -- a qualitative shift from DDoS/defacement to destructive attack.
- Akamai publishes 'Smash and Grab at Scale,' documenting 313 Team's agentic-AI-driven attacks on e-commerce APIs, active exploitation of CVE-2025-39391, and emerging AI-native TTPs (leaky faucet chatbot abuse, prompt injection/jailbreaks, AI token freeloading).
Sources cited for 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
- Smash and Grab at Scale: How Agentic AI Is Reshaping the Threat to Commerce
- 313 Team / Islamic Cyber Resistance -- HawkEye Threat Advisory
- CVE-2025-39391: WooCommerce Path Traversal / LFI Vulnerability
- WordPress Checkout Field Visibility for WooCommerce Plugin 1.2.3 Local File Inclusion Vulnerability
- 313 Team and the Iran-Israel Shadow War
- Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
- Exclusive Interview: 313 Team
- 149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
- Jupiter X Core WordPress Plugin Could Let Hackers Hijack Sites
Threats related to 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure
Detection coverage for TL-2026-1374
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1374 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.