Adversary Intelligence — 2026-05-03

Iran-Linked 313 Team Conducts DDoS Campaign Against Bluesky and Ubuntu Infrastructure

Beginning at approximately 11:40 PM PDT on April 15, Bluesky sustained a DDoS attack against its API that disrupted service for the platform's roughly 43.7 million users, per official company statements corroborated by TechCrunch on April 17 and Security Affairs on April 18. The Iran-linked group 313 Team, also identifying as the Islamic Cyber Resistance in Iraq, claimed responsibility on Telegram, as reported by Hackread citing Heise Medien; Bluesky did not publicly name the perpetrators. Service recovered by approximately 9 PM PDT on April 16, and Bluesky confirmed on April 18 that no unauthorized access to private user data had occurred. Hackread additionally reported the group targeted mastodon.social on April 20, with that platform experiencing limited disruption.

Analysis
Sequential targeting of Bluesky and mastodon.social within five days reflects deliberate focus on federated Western social media rather than opportunistic selection. Telegram claims under dual identities, 313 Team and Islamic Cyber Resistance in Iraq, signal audience mobilization alongside technical disruption as primary drivers. The absence of data exfiltration is consistent with Iranian state-aligned information environment operations targeting diaspora and opposition discourse. Attribution rests on the group's self-identification per a single Hackread report, with no independent technical corroboration. Iran-linked actors will likely conduct at least one additional disruptive attack against Western technology or social media infrastructure before August 2026, though the 313 Team may be an autonomous network exploiting Iranian-aligned framing for brand visibility rather than a directed state proxy.
1 sources
  1. Bluesky Online DDoS Attack Iran 313 Team - Hackread

View in full brief →

UNCLASSIFIED // OPEN SOURCE