Skip to main content

CYBER ADVERSARY DOSSIER

OPERATIONAL INTELLIGENCE DOSSIER

Identity Resolution and Strategic Attribution of Iranian State-Sponsored Cyber Adversaries

CURRENT AS OF JANUARY 2026

Operational Intelligence: This dossier provides exhaustive identity resolution of personnel staffing the Iranian regime's primary contractor nodes.

TABLE OF CONTENTS

01Strategic Context: The Industrialization of Iranian State Cyber Capabilities

The evolution of the Islamic Republic of Iran's offensive cyber capabilities represents one of the most significant shifts in the modern asymmetric warfare landscape. Following the watershed Stuxnet event, the Iranian regime—specifically the Supreme Council of Cyberspace (SCC), the Islamic Revolutionary Guard Corps (IRGC), and the Ministry of Intelligence and Security (MOIS)—initiated a comprehensive doctrine of "active defense" that has since mutated into a persistent, global offensive posture.

Unlike the centralized military cyber commands typical of Western or Russian doctrines, the Iranian model is characterized by a high degree of fragmentation and privatization. The regime relies heavily on a "contractor ecosystem"—a network of ostensibly private technology firms that function as fronts or specialized vendors for state intelligence requirements.

Key Characteristics of the Contractor Ecosystem

These entities are registered limited liability companies with tax identification numbers, physical offices in Tehran's business districts, and recruitment booths at major universities.

This ecosystem is bifurcated primarily between the IRGC (aggressive, disruptive operations) and the MOIS (long-term intelligence gathering and surveillance).

Strategic Timeline: Iranian Cyber Contractor Ecosystem

(2013 – 2021)

Entity Formation
Legal Action / Indictment
Intelligence Obtained
Cyber Attack / Operation

Target Dossier: Key Contractor Ecosystem Operatives

Personal Identifiable Information (PII) for notable indicted operatives

WANTED
GHOLAMREZA RAFATNEJAD
GHOLAMREZA RAFATNEJAD

Mabna Institute Founder

DOBMay 23, 1979
POBTabriz, Iran
ID137-582394-9
INDICTED MAR 2018
WANTED
EHSAN MOHAMMADI
EHSAN MOHAMMADI

Mabna Managing Director

DOBDec 25, 1980
POBTehran, Iran
ID006-718237-2
INDICTED MAR 2018
WANTED
BEHZAD MESRI
BEHZAD MESRI

Net Peygard CEO / HBO Hacker

DOBAug 26, 1988
POBNaghadeh, Iran
INDICTED NOV 2017
WANTED
MOHAMMAD HOSEIN MUSA KAZEMI
MOHAMMAD HOSEIN MUSA KAZEMI

Emennet Pasargad Operator

DOBJun 18, 1997
POBIran
ID0020372604
INDICTED NOV 2021

Iranian Cyber Contractor Network: Command & Targeting Structure

State Command
Primary Contractor
Secondary Contractor
Target

Figure 1: Hierarchical structure of Iranian cyber contractors and their targets

02The Mabna Institute Cluster: Industrial-Scale Intellectual Property Theft

The Mabna Institute serves as the archetype of the IRGC contractor model, illustrating the seamless blend of state objectives and private criminal enterprise. Founded in 2013, the institute was established with the specific mandate of assisting Iranian universities and scientific organizations in circumventing international sanctions to access research and technology.

Through subsidiary websites such as "Megapaper" and "Gigapaper," the principals of Mabna sold access to stolen academic journals and credentials to Iranian students and institutions, effectively creating a secondary market for their espionage products.

2.1 Leadership and Management Cadre

Gholamreza Rafatnejad (Founding Member)

Rafatnejad is identified as the primary architect of the Mabna Institute's hacking infrastructure. His role extended beyond mere management; he actively organized the campaigns, managed the stolen credentials, and maintained the critical liaison with the IRGC.

Personal Intelligence Dossier
AttributeDetail
Full NameGholamreza Rafatnejad
Date of Birth23 May 1979
Place of BirthTabriz, Iran
National ID (Code Melli)137-582394-9
Birth Certificate No.365
Physical CharacteristicsApprox. 200 lbs, 5'8"
RoleFounding member; coordinated university spearphishing campaigns

Ehsan Mohammadi (Managing Director)

Serving as co-founder alongside Rafatnejad, Mohammadi functioned as the Managing Director of the institute. His responsibilities included handling the financial aspects of the operations and the commercialization of stolen data through the institute's front companies.

Personal Intelligence Dossier
AttributeDetail
Full NameEhsan Mohammadi
Date of Birth25 Dec 1980
Place of BirthTehran, Iran
National ID (Code Melli)006-718237-2
Passport NumberU21669469 (Issued 25 Jul 2011, Expired 24 Jul 2016)
Birth Certificate No.7608
RoleManaging Director; organized university targeting

Abdollah Karima (Commercial Facilitator)

Karima represents the commercial nexus of the group, owning and operating "Falinoos Company," the corporate entity behind the "Megapaper" website.

Personal Intelligence Dossier
AttributeDetail
Full NameAbdollah Karima
Known AliasesVahid
Date of Birth21 Mar 1979
Place of BirthMashhad, Iran
National ID (Code Melli)093-343402-2
Birth Certificate No.4043
RoleOwner of Falinoos Company; sold stolen academic materials

2.2 Operational Personnel and Contractors

Mostafa Sadeghi (Hacker / Affiliate)

Sadeghi is noted as a prolific hacker within the network, personally responsible for compromising over 1,000 professor accounts.

Personal Intelligence Dossier
AttributeDetail
Full NameMostafa Sadeghi
Date of Birth19 Jan 1990 (alt. 20 Jan 1990, 19 Jan 1991, 20 Jan 1991)
National ID (Code Melli)2500094065
Physical Characteristics5'7", 145 lbs
RoleHacker/Affiliate; maintained financial interest in data sales sites

Seyed Ali Mirkarimi (Hacker / Contractor)

Personal Intelligence Dossier
AttributeDetail
Full NameSeyed Ali Mirkarimi
Date of Birth20 Sep 1983
Place of BirthZanjan, Iran
National ID (Code Melli)428-486320-7
Passport Number86486868
Birth Certificate No.1973
RoleHacker/Contractor; domain registration and email crafting

Sajjad Tahmasebi (Contractor)

Personal Intelligence Dossier
AttributeDetail
Full NameSajjad Tahmasebi
Date of Birth19 Jun 1987
National ID (Code Melli)428-576368-0
Birth Certificate No.6686
RoleContractor; reconnaissance and surveillance

Abuzar Gohari Moqadam (Professor / Affiliate)

Personal Intelligence Dossier
AttributeDetail
Full NameAbuzar Gohari Moqadam
Date of Birth16 Sep 1980 (alt. 17 Sep 1980)
Place of BirthZabol, Iran
National ID (Code Melli)367-353055-063
Passport NumberV29385211 (Issued 19 Feb 2014, Expired 19 Feb 2019)
Birth Certificate No.455
RoleProfessor/Affiliate; exchanged credentials and provided targeting intelligence

Mohammed Reza Sabahi (Contractor)

Personal Intelligence Dossier
AttributeDetail
Full NameMohammed Reza Sabahi
Known AliasesFaraz
Date of Birth02 Dec 1991
Place of BirthTehran, Iran
National ID (Code Melli)041-023144-4
RoleContractor; targeting lists and database cataloging

Roozbeh Sabahi (Contractor)

Personal Intelligence Dossier
AttributeDetail
Full NameRoozbeh Sabahi
Date of Birth08 Mar 1994 (alt. 09 Mar 1994)
Place of BirthIran
Physical Characteristics5'11", 180 lbs
RoleContractor; credential organization and hacking execution
Corporate Address
  • Ansariyeh Boulevard, 6th Bustan, Plaque 488, Zanjan, Iran (Postal Code: 4515736541)
  • Mirdamad, Naft Jonubi, Taban Alley, Plaque 2/1, Unit 102, Tehran, Iran
  • East Shahid Hemmat Highway, North Emam Ali Highway, Town of Qa'em, Banafsheh Street, Second Door, Plaque 2, Tehran

03Rana Intelligence Computing Company (APT39): The Surveillance Apparatus

While the Mabna Institute focused on external intellectual property theft, Rana Intelligence Computing Company—tracked in the cybersecurity community as APT39, Chafer, or Cadelspy—functioned as the internal surveillance arm of the Ministry of Intelligence and Security (MOIS).

Rana's mandate was explicitly focused on the monitoring of Iranian citizens, dissidents, journalists, and refugees, as well as foreign travel and telecommunications firms.

Corporate Identity
  • Entity Name: Rana Intelligence Computing Company (aka Rana Corp, Rana Institute)
  • Sanctions Program: IRAN-HR
  • Operational Context: Subordinate to MOIS

The MOIS utilizes a "knowledge-based" recruitment strategy, turning top-tier computer science graduates into tools of state repression under the guise of legitimate employment.

Malware Tools Developed

Cadelspy: A malware family used for espionage

Remexi: A tool often used for tracking and surveillance

Android Surveillance Tools: Real-time location and communications tracking via smartphones

04ITSecTeam and Mersad: The Financial Sector Aggressors

The ITSecTeam (Amn Pardazesh Kharazmi) and Mersad Company represent an earlier, yet foundational generation of IRGC contractors. They are infamous for Operation Ababil—the massive Distributed Denial of Service (DDoS) campaigns against the U.S. financial sector between 2011 and 2013.

4.1 ITSecTeam Personnel

Ahmad Fathi (Director)

Fathi was the leader of the ITSecTeam defendants and supervised the botnet operations.

Personal Intelligence Dossier
AttributeDetail
Full NameAhmad Fathi
Known AliasesM3S3C3, M3HRAN, Farhad Mohammadi
Date of Birth11 Sep 1978
Place of BirthIran
National ID (Code Melli)5725729366035
RoleDirector; coordinated attacks against U.S. banks
Physical AddressUnit 2, No. 129, Mir Ali Akbari St, Motahari Avenue, Tehran

Hamid Firoozi (Network Manager)

Firoozi is a particularly significant figure due to his role in procuring the servers used in the attacks and his specific intrusion into the Bowman Dam SCADA system in Rye, New York.

Personal Intelligence Dossier
AttributeDetail
Full NameHamid Firoozi
Date of Birth06 Aug 1981 (alts: 01 Jan 1980, 23 Jun 1981)
Place of BirthIran
Physical Characteristics5'8", 170 lbs
RoleNetwork Manager; procured servers and accessed Bowman Dam control systems

Amin Shokohi (Hacker)

Shokohi helped build the ITSecTeam botnet and created malware used in DDoS attacks. Crucially, Shokohi received credit towards his mandatory military service for his computer intrusion work.

Personal Intelligence Dossier
AttributeDetail
Full NameAmin Shokohi
Known AliasesPejvak
Date of Birth11 Jul 1990 (alts: 11 Jul 1989, 05 Aug 1981)
Place of BirthKaraj, Iran
RoleHacker; malware development and botnet construction

4.2 Mersad Company Personnel

Mersad Company was founded by members of former hacktivist groups "Sun Army" and "Ashiyane Digital Security Team," illustrating the pipeline from "patriotic hacktivist" to state contractor.

Sadegh Ahmadzadegan (Co-Founder)

Personal Intelligence Dossier
AttributeDetail
Full NameSadegh Ahmadzadegan
Known AliasesNitr0jen26, Nitr0jen
Date of Birth27 Oct 1992 (alt: 27 Aug 1991)
Place of BirthIran
RoleCo-founder; managed Mersad botnet and trained intelligence personnel

Omid Ghaffarinia (Co-Founder)

Personal Intelligence Dossier
AttributeDetail
Full NameOmid Ghaffarinia
Known AliasesPLuS
Date of Birth24 Jun 1990
Place of BirthIran
RoleCo-founder; developed exploit code for server compromise

Nader Saedi (Employee)

Personal Intelligence Dossier
AttributeDetail
Full NameNader Saedi
Known AliasesTurk Server
Date of Birth20 Feb 1990
Place of BirthMianeh, Iran
RoleEmployee; scriptwriter for vulnerability scanning and DDoS execution

Sina Keissar (Employee)

Personal Intelligence Dossier
AttributeDetail
Full NameSina Keissar
Date of Birth20 May 1990
Place of BirthIran
RoleEmployee; infrastructure procurement and testing

05Emennet Pasargad (Charming Kitten): The Election Interference Nexus

The group tracked as Charming Kitten (also known as APT35 or Phosphorus) serves as a prime case study in the "burn and pivot" tactic utilized by Iranian cyber actors. Following the exposure and designation of Net Peygard Samavat Company in 2019, the group's leadership did not disband. Instead, they reformed under the name Emennet Pasargad to continue their operations.

This reconstituted entity was directly responsible for the attempted interference in the 2020 U.S. Presidential Election, utilizing threatening emails and disinformation campaigns.

5.1 Leadership and Continuity of Command

Mohammad Bagher Shirinkar (aka Mojtaba Tehrani)

Shirinkar serves as the critical continuity figure connecting the old Net Peygard Samavat entity to the new Emennet Pasargad.

Personal Intelligence Dossier
AttributeDetail
Full NameMohammad Bagher Shirinkar
Known AliasesMojtaba Tehrani
Date of Birth21 Sep 1979
National ID (Code Melli)0067948431
RoleManager of Emennet Pasargad; previously provided technical support to IRGC-EWCD

5.2 The 2020 Election Interference Cell

Seyyed Mohammad Hosein Musa Kazemi (aka Hosein Zamani)

Personal Intelligence Dossier
AttributeDetail
Full NameSeyyed Mohammad Hosein Musa Kazemi
Known AliasesHosein Zamani
Date of Birth18 Jun 1997
National ID (Code Melli)0020372604
RoleTechnical operator; server compromise, content drafting, and media company intrusion

Sajjad Kashian (aka Kiarash Nabavi)

Personal Intelligence Dossier
AttributeDetail
Full NameSajjad Kashian
Known AliasesKiarash Nabavi
Date of Birth17 Sep 1994
National ID (Code Melli)4560134669
RoleInfrastructure manager; social media asset procurement
Board Members of Emennet Pasargad
  • Mostafa Sarmadi: DOB 22 Aug 1987; National ID 0082389985
  • Seyyed Mehdi Hashemi Toghroljerdi: DOB 19 Apr 1973; National ID 3091111628
  • Hosein Akbari Nodeh: DOB 27 Dec 1980; National ID 0062245260

5.3 The Predecessor: Net Peygard Samavat

Behzad Mesri (aka "Skote Vahshat")

Mesri gained international notoriety for the hack and extortion attempt against HBO.

Personal Intelligence Dossier
AttributeDetail
Full NameBehzad Mesri
Known AliasesSkote Vahshat
Date of Birth26 Aug 1988
Place of BirthNaghadeh, Iran
RoleCEO of Net Peygard; orchestrated the HBO hack

06The MuddyWater (MOIS) Nexus and Training Infrastructure

Intelligence analysis has revealed the internal workings of the MOIS cyber operations, specifically the group known as MuddyWater (also tracked as Static Kitten, Seedworm, and Yellow Nix).

6.1 Ravin Academy: The Training Ground

Ravin Academy is identified not merely as an educational institution but as an operational front for the MOIS. It trains individuals in offensive cyber techniques—such as malware analysis, penetration testing, and social engineering.

Corporate Identity
  • Entity Name: Ravin Academy (aka Ravin Cybersecurity)
  • Address: No. 105 Motahari St, Suleiman Khater St, Tehran, Iran
  • Registration No.: 49135

6.2 Identified MuddyWater Operators

Seyed Mojtaba Mostafavi

Mostafavi is a central figure who has been sanctioned. He co-founded Ravin Academy and is directly linked to the MuddyWater intrusion set. Prior to Ravin, he held the position of Chief Strategy Officer (CSO) at ArvanCloud (2015-2019).

Personal Intelligence Dossier
AttributeDetail
Full NameSeyed Mojtaba Mostafavi
National ID (Code Melli)0080467741
RoleChairman of the Board at Ravin Academy; linked to MuddyWater

Farzin Karimi (aka Farzin Karimi Mazlganchai)

Karimi is alleged to be a former leader of MuddyWater operations who transitioned into a training and mentorship role at Ravin Academy.

Personal Intelligence Dossier
AttributeDetail
Full NameFarzin Karimi
Known AliasesFarzin Karimi Mazlganchai
National ID (Code Melli)0440273961
RoleCo-founder and Chairman of the Board of Directors at Ravin Academy

07Emerging Threats and Peripheral Nodes

Beyond the primary clusters of Mabna, Rana, and Emennet, the research identifies peripheral entities that support the broader cyber ecosystem of the regime.

Andisheh Negar Pars (Agonizing Serpens / Agrius)

This entity is linked to the Agonizing Serpens / Agrius threat group, known for conducting destructive wiper attacks disguised as ransomware.

  • Sayyed Mohammad Reza Seddighi Saber: DOB 24 Aug 1974; National ID 2739202830
  • Ahmad Haghighat Talab: DOB 12 Oct 1963; National ID 4131686491
  • Mohammad Reza Mehdipur: DOB 06 Aug 1975; National ID 1249481643
Najee Technology & Afkar System (IRGC Affiliates)

These companies were designated for providing material support to the IRGC's cyber activities.

  • Mansour Ahmadi: Owner of Najee Technology. DOB 07 Jul 1988; National ID 0453740243
  • Ahmad Khatibi Aghda: Manager of Afkar System. DOB 21 Mar 1977
  • Mojtaba Haji Hosseini: DOB 1991; National ID 4480031332

END OF DOSSIER