CYBER ADVERSARY DOSSIER
OPERATIONAL INTELLIGENCE DOSSIER
Identity Resolution and Strategic Attribution of Iranian State-Sponsored Cyber Adversaries
CURRENT AS OF JANUARY 2026
Operational Intelligence: This dossier provides exhaustive identity resolution of personnel staffing the Iranian regime's primary contractor nodes.
TABLE OF CONTENTS
01Strategic Context: The Industrialization of Iranian State Cyber Capabilities
The evolution of the Islamic Republic of Iran's offensive cyber capabilities represents one of the most significant shifts in the modern asymmetric warfare landscape. Following the watershed Stuxnet event, the Iranian regime—specifically the Supreme Council of Cyberspace (SCC), the Islamic Revolutionary Guard Corps (IRGC), and the Ministry of Intelligence and Security (MOIS)—initiated a comprehensive doctrine of "active defense" that has since mutated into a persistent, global offensive posture.
Unlike the centralized military cyber commands typical of Western or Russian doctrines, the Iranian model is characterized by a high degree of fragmentation and privatization. The regime relies heavily on a "contractor ecosystem"—a network of ostensibly private technology firms that function as fronts or specialized vendors for state intelligence requirements.
These entities are registered limited liability companies with tax identification numbers, physical offices in Tehran's business districts, and recruitment booths at major universities.
This ecosystem is bifurcated primarily between the IRGC (aggressive, disruptive operations) and the MOIS (long-term intelligence gathering and surveillance).
Strategic Timeline: Iranian Cyber Contractor Ecosystem
(2013 – 2021)
Target Dossier: Key Contractor Ecosystem Operatives
Personal Identifiable Information (PII) for notable indicted operatives

GHOLAMREZA RAFATNEJAD
Mabna Institute Founder

EHSAN MOHAMMADI
Mabna Managing Director

BEHZAD MESRI
Net Peygard CEO / HBO Hacker

MOHAMMAD HOSEIN MUSA KAZEMI
Emennet Pasargad Operator
Iranian Cyber Contractor Network: Command & Targeting Structure
Figure 1: Hierarchical structure of Iranian cyber contractors and their targets
02The Mabna Institute Cluster: Industrial-Scale Intellectual Property Theft
The Mabna Institute serves as the archetype of the IRGC contractor model, illustrating the seamless blend of state objectives and private criminal enterprise. Founded in 2013, the institute was established with the specific mandate of assisting Iranian universities and scientific organizations in circumventing international sanctions to access research and technology.
Through subsidiary websites such as "Megapaper" and "Gigapaper," the principals of Mabna sold access to stolen academic journals and credentials to Iranian students and institutions, effectively creating a secondary market for their espionage products.
2.1 Leadership and Management Cadre
Gholamreza Rafatnejad (Founding Member)
Rafatnejad is identified as the primary architect of the Mabna Institute's hacking infrastructure. His role extended beyond mere management; he actively organized the campaigns, managed the stolen credentials, and maintained the critical liaison with the IRGC.
| Attribute | Detail |
|---|---|
| Full Name | Gholamreza Rafatnejad |
| Date of Birth | 23 May 1979 |
| Place of Birth | Tabriz, Iran |
| National ID (Code Melli) | 137-582394-9 |
| Birth Certificate No. | 365 |
| Physical Characteristics | Approx. 200 lbs, 5'8" |
| Role | Founding member; coordinated university spearphishing campaigns |
Ehsan Mohammadi (Managing Director)
Serving as co-founder alongside Rafatnejad, Mohammadi functioned as the Managing Director of the institute. His responsibilities included handling the financial aspects of the operations and the commercialization of stolen data through the institute's front companies.
| Attribute | Detail |
|---|---|
| Full Name | Ehsan Mohammadi |
| Date of Birth | 25 Dec 1980 |
| Place of Birth | Tehran, Iran |
| National ID (Code Melli) | 006-718237-2 |
| Passport Number | U21669469 (Issued 25 Jul 2011, Expired 24 Jul 2016) |
| Birth Certificate No. | 7608 |
| Role | Managing Director; organized university targeting |
Abdollah Karima (Commercial Facilitator)
Karima represents the commercial nexus of the group, owning and operating "Falinoos Company," the corporate entity behind the "Megapaper" website.
| Attribute | Detail |
|---|---|
| Full Name | Abdollah Karima |
| Known Aliases | Vahid |
| Date of Birth | 21 Mar 1979 |
| Place of Birth | Mashhad, Iran |
| National ID (Code Melli) | 093-343402-2 |
| Birth Certificate No. | 4043 |
| Role | Owner of Falinoos Company; sold stolen academic materials |
2.2 Operational Personnel and Contractors
Mostafa Sadeghi (Hacker / Affiliate)
Sadeghi is noted as a prolific hacker within the network, personally responsible for compromising over 1,000 professor accounts.
| Attribute | Detail |
|---|---|
| Full Name | Mostafa Sadeghi |
| Date of Birth | 19 Jan 1990 (alt. 20 Jan 1990, 19 Jan 1991, 20 Jan 1991) |
| National ID (Code Melli) | 2500094065 |
| Physical Characteristics | 5'7", 145 lbs |
| Role | Hacker/Affiliate; maintained financial interest in data sales sites |
Seyed Ali Mirkarimi (Hacker / Contractor)
| Attribute | Detail |
|---|---|
| Full Name | Seyed Ali Mirkarimi |
| Date of Birth | 20 Sep 1983 |
| Place of Birth | Zanjan, Iran |
| National ID (Code Melli) | 428-486320-7 |
| Passport Number | 86486868 |
| Birth Certificate No. | 1973 |
| Role | Hacker/Contractor; domain registration and email crafting |
Sajjad Tahmasebi (Contractor)
| Attribute | Detail |
|---|---|
| Full Name | Sajjad Tahmasebi |
| Date of Birth | 19 Jun 1987 |
| National ID (Code Melli) | 428-576368-0 |
| Birth Certificate No. | 6686 |
| Role | Contractor; reconnaissance and surveillance |
Abuzar Gohari Moqadam (Professor / Affiliate)
| Attribute | Detail |
|---|---|
| Full Name | Abuzar Gohari Moqadam |
| Date of Birth | 16 Sep 1980 (alt. 17 Sep 1980) |
| Place of Birth | Zabol, Iran |
| National ID (Code Melli) | 367-353055-063 |
| Passport Number | V29385211 (Issued 19 Feb 2014, Expired 19 Feb 2019) |
| Birth Certificate No. | 455 |
| Role | Professor/Affiliate; exchanged credentials and provided targeting intelligence |
Mohammed Reza Sabahi (Contractor)
| Attribute | Detail |
|---|---|
| Full Name | Mohammed Reza Sabahi |
| Known Aliases | Faraz |
| Date of Birth | 02 Dec 1991 |
| Place of Birth | Tehran, Iran |
| National ID (Code Melli) | 041-023144-4 |
| Role | Contractor; targeting lists and database cataloging |
Roozbeh Sabahi (Contractor)
| Attribute | Detail |
|---|---|
| Full Name | Roozbeh Sabahi |
| Date of Birth | 08 Mar 1994 (alt. 09 Mar 1994) |
| Place of Birth | Iran |
| Physical Characteristics | 5'11", 180 lbs |
| Role | Contractor; credential organization and hacking execution |
- ▸Ansariyeh Boulevard, 6th Bustan, Plaque 488, Zanjan, Iran (Postal Code: 4515736541)
- ▸Mirdamad, Naft Jonubi, Taban Alley, Plaque 2/1, Unit 102, Tehran, Iran
- ▸East Shahid Hemmat Highway, North Emam Ali Highway, Town of Qa'em, Banafsheh Street, Second Door, Plaque 2, Tehran
03Rana Intelligence Computing Company (APT39): The Surveillance Apparatus
While the Mabna Institute focused on external intellectual property theft, Rana Intelligence Computing Company—tracked in the cybersecurity community as APT39, Chafer, or Cadelspy—functioned as the internal surveillance arm of the Ministry of Intelligence and Security (MOIS).
Rana's mandate was explicitly focused on the monitoring of Iranian citizens, dissidents, journalists, and refugees, as well as foreign travel and telecommunications firms.
- Entity Name: Rana Intelligence Computing Company (aka Rana Corp, Rana Institute)
- Sanctions Program: IRAN-HR
- Operational Context: Subordinate to MOIS
The MOIS utilizes a "knowledge-based" recruitment strategy, turning top-tier computer science graduates into tools of state repression under the guise of legitimate employment.
Cadelspy: A malware family used for espionage
Remexi: A tool often used for tracking and surveillance
Android Surveillance Tools: Real-time location and communications tracking via smartphones
04ITSecTeam and Mersad: The Financial Sector Aggressors
The ITSecTeam (Amn Pardazesh Kharazmi) and Mersad Company represent an earlier, yet foundational generation of IRGC contractors. They are infamous for Operation Ababil—the massive Distributed Denial of Service (DDoS) campaigns against the U.S. financial sector between 2011 and 2013.
4.1 ITSecTeam Personnel
Ahmad Fathi (Director)
Fathi was the leader of the ITSecTeam defendants and supervised the botnet operations.
| Attribute | Detail |
|---|---|
| Full Name | Ahmad Fathi |
| Known Aliases | M3S3C3, M3HRAN, Farhad Mohammadi |
| Date of Birth | 11 Sep 1978 |
| Place of Birth | Iran |
| National ID (Code Melli) | 5725729366035 |
| Role | Director; coordinated attacks against U.S. banks |
| Physical Address | Unit 2, No. 129, Mir Ali Akbari St, Motahari Avenue, Tehran |
Hamid Firoozi (Network Manager)
Firoozi is a particularly significant figure due to his role in procuring the servers used in the attacks and his specific intrusion into the Bowman Dam SCADA system in Rye, New York.
| Attribute | Detail |
|---|---|
| Full Name | Hamid Firoozi |
| Date of Birth | 06 Aug 1981 (alts: 01 Jan 1980, 23 Jun 1981) |
| Place of Birth | Iran |
| Physical Characteristics | 5'8", 170 lbs |
| Role | Network Manager; procured servers and accessed Bowman Dam control systems |
Amin Shokohi (Hacker)
Shokohi helped build the ITSecTeam botnet and created malware used in DDoS attacks. Crucially, Shokohi received credit towards his mandatory military service for his computer intrusion work.
| Attribute | Detail |
|---|---|
| Full Name | Amin Shokohi |
| Known Aliases | Pejvak |
| Date of Birth | 11 Jul 1990 (alts: 11 Jul 1989, 05 Aug 1981) |
| Place of Birth | Karaj, Iran |
| Role | Hacker; malware development and botnet construction |
4.2 Mersad Company Personnel
Mersad Company was founded by members of former hacktivist groups "Sun Army" and "Ashiyane Digital Security Team," illustrating the pipeline from "patriotic hacktivist" to state contractor.
Sadegh Ahmadzadegan (Co-Founder)
| Attribute | Detail |
|---|---|
| Full Name | Sadegh Ahmadzadegan |
| Known Aliases | Nitr0jen26, Nitr0jen |
| Date of Birth | 27 Oct 1992 (alt: 27 Aug 1991) |
| Place of Birth | Iran |
| Role | Co-founder; managed Mersad botnet and trained intelligence personnel |
Omid Ghaffarinia (Co-Founder)
| Attribute | Detail |
|---|---|
| Full Name | Omid Ghaffarinia |
| Known Aliases | PLuS |
| Date of Birth | 24 Jun 1990 |
| Place of Birth | Iran |
| Role | Co-founder; developed exploit code for server compromise |
Nader Saedi (Employee)
| Attribute | Detail |
|---|---|
| Full Name | Nader Saedi |
| Known Aliases | Turk Server |
| Date of Birth | 20 Feb 1990 |
| Place of Birth | Mianeh, Iran |
| Role | Employee; scriptwriter for vulnerability scanning and DDoS execution |
Sina Keissar (Employee)
| Attribute | Detail |
|---|---|
| Full Name | Sina Keissar |
| Date of Birth | 20 May 1990 |
| Place of Birth | Iran |
| Role | Employee; infrastructure procurement and testing |
05Emennet Pasargad (Charming Kitten): The Election Interference Nexus
The group tracked as Charming Kitten (also known as APT35 or Phosphorus) serves as a prime case study in the "burn and pivot" tactic utilized by Iranian cyber actors. Following the exposure and designation of Net Peygard Samavat Company in 2019, the group's leadership did not disband. Instead, they reformed under the name Emennet Pasargad to continue their operations.
This reconstituted entity was directly responsible for the attempted interference in the 2020 U.S. Presidential Election, utilizing threatening emails and disinformation campaigns.
5.1 Leadership and Continuity of Command
Mohammad Bagher Shirinkar (aka Mojtaba Tehrani)
Shirinkar serves as the critical continuity figure connecting the old Net Peygard Samavat entity to the new Emennet Pasargad.
| Attribute | Detail |
|---|---|
| Full Name | Mohammad Bagher Shirinkar |
| Known Aliases | Mojtaba Tehrani |
| Date of Birth | 21 Sep 1979 |
| National ID (Code Melli) | 0067948431 |
| Role | Manager of Emennet Pasargad; previously provided technical support to IRGC-EWCD |
5.2 The 2020 Election Interference Cell
Seyyed Mohammad Hosein Musa Kazemi (aka Hosein Zamani)
| Attribute | Detail |
|---|---|
| Full Name | Seyyed Mohammad Hosein Musa Kazemi |
| Known Aliases | Hosein Zamani |
| Date of Birth | 18 Jun 1997 |
| National ID (Code Melli) | 0020372604 |
| Role | Technical operator; server compromise, content drafting, and media company intrusion |
Sajjad Kashian (aka Kiarash Nabavi)
| Attribute | Detail |
|---|---|
| Full Name | Sajjad Kashian |
| Known Aliases | Kiarash Nabavi |
| Date of Birth | 17 Sep 1994 |
| National ID (Code Melli) | 4560134669 |
| Role | Infrastructure manager; social media asset procurement |
- Mostafa Sarmadi: DOB 22 Aug 1987; National ID 0082389985
- Seyyed Mehdi Hashemi Toghroljerdi: DOB 19 Apr 1973; National ID 3091111628
- Hosein Akbari Nodeh: DOB 27 Dec 1980; National ID 0062245260
5.3 The Predecessor: Net Peygard Samavat
Behzad Mesri (aka "Skote Vahshat")
Mesri gained international notoriety for the hack and extortion attempt against HBO.
| Attribute | Detail |
|---|---|
| Full Name | Behzad Mesri |
| Known Aliases | Skote Vahshat |
| Date of Birth | 26 Aug 1988 |
| Place of Birth | Naghadeh, Iran |
| Role | CEO of Net Peygard; orchestrated the HBO hack |
06The MuddyWater (MOIS) Nexus and Training Infrastructure
Intelligence analysis has revealed the internal workings of the MOIS cyber operations, specifically the group known as MuddyWater (also tracked as Static Kitten, Seedworm, and Yellow Nix).
6.1 Ravin Academy: The Training Ground
Ravin Academy is identified not merely as an educational institution but as an operational front for the MOIS. It trains individuals in offensive cyber techniques—such as malware analysis, penetration testing, and social engineering.
- Entity Name: Ravin Academy (aka Ravin Cybersecurity)
- Address: No. 105 Motahari St, Suleiman Khater St, Tehran, Iran
- Registration No.: 49135
6.2 Identified MuddyWater Operators
Seyed Mojtaba Mostafavi
Mostafavi is a central figure who has been sanctioned. He co-founded Ravin Academy and is directly linked to the MuddyWater intrusion set. Prior to Ravin, he held the position of Chief Strategy Officer (CSO) at ArvanCloud (2015-2019).
| Attribute | Detail |
|---|---|
| Full Name | Seyed Mojtaba Mostafavi |
| National ID (Code Melli) | 0080467741 |
| Role | Chairman of the Board at Ravin Academy; linked to MuddyWater |
Farzin Karimi (aka Farzin Karimi Mazlganchai)
Karimi is alleged to be a former leader of MuddyWater operations who transitioned into a training and mentorship role at Ravin Academy.
| Attribute | Detail |
|---|---|
| Full Name | Farzin Karimi |
| Known Aliases | Farzin Karimi Mazlganchai |
| National ID (Code Melli) | 0440273961 |
| Role | Co-founder and Chairman of the Board of Directors at Ravin Academy |
07Emerging Threats and Peripheral Nodes
Beyond the primary clusters of Mabna, Rana, and Emennet, the research identifies peripheral entities that support the broader cyber ecosystem of the regime.
This entity is linked to the Agonizing Serpens / Agrius threat group, known for conducting destructive wiper attacks disguised as ransomware.
- Sayyed Mohammad Reza Seddighi Saber: DOB 24 Aug 1974; National ID 2739202830
- Ahmad Haghighat Talab: DOB 12 Oct 1963; National ID 4131686491
- Mohammad Reza Mehdipur: DOB 06 Aug 1975; National ID 1249481643
These companies were designated for providing material support to the IRGC's cyber activities.
- Mansour Ahmadi: Owner of Najee Technology. DOB 07 Jul 1988; National ID 0453740243
- Ahmad Khatibi Aghda: Manager of Afkar System. DOB 21 Mar 1977
- Mojtaba Haji Hosseini: DOB 1991; National ID 4480031332
END OF DOSSIER