Skip to main content

IRGC CYBER ECOSYSTEM

FORENSIC INTELLIGENCE REPORT 2014-2026

From the "Contractor Model" to Cyber–Kinetic Convergence

LAST UPDATED: JANUARY 2026

Intelligence Assessment: This forensic report contains actionable intelligence on the IRGC offensive cyber ecosystem, including corporate fronts, operators, and state-aligned contractors engaged in cyber-enabled kinetic operations.

TABLE OF CONTENTS

01Why This Ecosystem Matters

Modern cyber conflict is not just about code. It is sustained by a human, organizational, and corporate backbone. What stands out from late 2024 through January 2026 is a clear shift: the IRGC and MOIS are no longer content with a neat separation between "espionage," "propaganda," and "disruption." Instead, they are pushing a doctrine of cyber-enabled kinetic operations.

At the same time, hacktivist disclosures (notably Lab Dookhtegan and Read My Lips), publicly unsealed indictments in September 2024, and sanctions against cyber contractors have made it possible to outline "who does what" inside the ecosystem.

02Command Architecture

The IRGC's offensive capabilities generally draw from two major lines:

Strategic Reality

Cyber is no longer a nuisance tool; it is increasingly integrated into core regime objectives.

IRGC Cyber Proxy Network: Command and Control Structure

Military Command
Contractor / Front Co.
Ransomware Activity

Figure 1: The operational hierarchy linking the IRGC Intelligence Organization (IRGC-IO) to its primary front companies.

03The Contractor Model & Corporate Mask

A central finding is the IRGC's institutionalized Contractor Model: legally registered, pseudo-private entities execute state-directed operations and, in some instances, participate in financially motivated cybercrime—an arrangement often described as "state-tolerated moonlighting."

Three recurring nodes in this model:

Key Contractor/Front Companies (Corporate Registration Overview)
CompanyCorporate National IDReg. No.AddressPostal Code
Najee Technology Hooshmand Fater1400833539736157Karaj, Rajaee Shahr, Phase 3...3146815441
Afkar System Yazd10860176637Yazd, Central Area, 31st Alley...8916984626
Emennet PasargadTehran (details changed over time)
Note: The addresses above are company office/registration addresses, not personal residences.

04The Human Layer: Executives & Operators

This ecosystem ultimately runs on people: executives who manage the corporate cover and operators who conduct intrusion, persistence, and data collection.

Leadership & Management

Senior Leadership
Name (English)Name (Farsi)RoleDOBNational IDPlace of Birth
Mansour Ahmadiمنصور احمدیManaging Director, Najee07 Jul 19880453740243Shemiran, Tehran
Ahmad Khatibi Aghdaاحمد خطیبی عقداManaging Director, Afkar21 Mar 1977Ardakan, Yazd

Mansour Ahmadi represents a younger cohort of trusted technical managers; Ahmad Khatibi Aghda is older and may bridge traditional command layers and younger technical teams.

Operatives & Facilitators

Operators
Name (English)Name (Farsi)DOBNational IDPassportPlace of Birth
Amir Hossein Nikaeen Ravariامیرحسین نیک‌آئین راوری13 Apr 19924480046429Meybod, Yazd
Aliakbar Rashidi-Barjiniعلی‌اکبر رشیدی بارجینی30 Apr 19914480034870Meybod, Yazd
Mohammad Shakeri-Ashtijehمحمد شاکری اشتیجه28 Nov 19970371588723B50759562Qom
Mojtaba Haji Hosseiniمجتبی حاجی حسینی19914480031332Meybod, Yazd
Mostafa Haji Hosseiniمصطفی حاجی حسینی19914480031340Meybod, Yazd
Mohammad Agha Ahmadiمحمد آقااحمدی01 Mar 19954890244441Savojbolagh, Alborz
Ali Agha-Ahmadiعلی آقااحمدی4899768060Savojbolagh, Alborz
Demographic Pattern

Early-to-mid 1990s birth years and geographic clustering (notably Yazd/Meybod) point to localized recruitment around specific contractors.

05APT42 / Mint Sandstorm & September 2024 Indictments

The cluster tracked as APT42 / Mint Sandstorm is characterized as a highly targeted, HUMINT-aligned capability: interactive social engineering, credible professional personas, and precise targeting of individuals and campaigns.

The 2024 U.S. Election Operation

In unsealed September 2024 charging documents, three individuals were accused of executing a targeted hacking campaign against email accounts associated with the U.S. presidential election (with specific attention on the Donald Trump campaign) and then attempted to move stolen material into political and media circulation.

Indicted Operators

September 2024 Indictment Group
NameOperational DescriptionDOBPlace of BirthAliases / NotesStatus
Masoud JaliliAccess acquisition; alias: "1028"08 Dec 1987TehranBirth Cert No: 49332Indicted; sanctioned
Seyyed Ali AghamiriSocial engineering / infrastructure24 Jun 1990TehranBlack hair, hazel eyesIndicted Sep 2024
Yaser BalaghiTechnical intrusion support19 Sep 1988TehranWool3n.H4t; ~2014 (Rocket Kitten)Indicted Sep 2024

Target Dossier: Indicted Mint Sandstorm Operatives (Sep 2024)

Personal Identifiable Information (PII) for the three primary Mint Sandstorm operatives indicted for the 2024 Trump Campaign hack.

WANTED
MASOUD JALILI
MASOUD JALILI

Aliases: Masud Jalili, Mas'ud Jalili, "1028"

DOBDecember 8, 1987
POBTehran, Iran
NATIONALITYIranian
HAIR/EYESBlack / Brown
LANGUAGESFarsi, English
National ID0079491391
INDICTED SEP 2024
WANTED
SEYYED ALI AGHAMIRI
SEYYED ALI AGHAMIRI
DOBJune 24, 1990
POBTehran, Iran
NATIONALITYIranian
HAIR/EYESBlack / Hazel
LANGUAGESFarsi, English
INDICTED SEP 2024
WANTED
YASER BALAGHI
YASER BALAGHI

Aliases: Wool3n.H4t; ~2014 (Rocket Kitten)

DOBSeptember 19, 1988
POBTehran, Iran
NATIONALITYIranian
HAIR/EYESBlack / Brown
LANGUAGESFarsi, English
INDICTED SEP 2024

06Contractor Lineage: Emennet Pasargad

To understand the present, you have to trace the earlier contractor lineage:

Behzad Mesri Profile
NameAliasDOBPlace of BirthNational IDAnalytical Note
Behzad MesriSkote Vahshat26 Aug 1988Naghadeh2909905624Hybrid threat: financial crime + state ties

07Hacktivist Counter-Intelligence

On the opposing side, hacktivist activity has imposed real operational friction by exposing identities and contractor data.

Operational Impact

Psychological pressure and forced personnel rotation and corporate restructuring—especially through disclosures tied to Najee and related clusters such as "Sahand."

08Cyber to Kinetic: The Fanava Incident

Cyber–kinetic convergence becomes concrete when digital access produces operational, physical-world consequences.

The Fanava Group Incident (August 2025)

A supply-chain compromise involving Fanava Group reportedly resulted in the removal or disabling of Falcon software across systems connected to maritime platforms. The stated outcome: disruption affecting 116 vessels (including 39 tankers and 25 cargo ships).

Examples of disclosed internal structure (directory names):

Kinetic-Aligned Clusters

09Domestic Control: Companies & Surveillance

Domestic control is the second major pillar: firms enabling filtering, DPI, VPN suppression, and influence operations.

Key Firms and Executives

Companies and Leadership (Domestic Control / Influence Enabling)
CompanyRoleKey ExecutiveTitleLocation
Sahab PardazSocial media filtering, DPI, censorshipMohammad Zandi AliabadiChairTehran
Sahab PardazHossein Zandi AliabadiVice ChairTehran
Sahab PardazFatemeh HaghshenasCEOTehran
Douran SoftwareVPN blocking, content controlAlireza AbedinejadCEOTehran
Douran SoftwareAmer NajafianpourChairTehran
Douran SoftwareSoheila KasaeiVice ChairTehran
Ravand CybertechInfluence ops; attributed to MOIS(entity-level)Toronto

Reported Sahab Pardaz office locations:

Surveillance-Ready Platforms

10Military-Academic Integration: MUT

MUT is described as a key R&D node connected to MODAFL, spanning cyber defense, cryptography, and sensitive technologies.

Named figures:

11Financial & Strategic Enablers

Cross-border operations require finance and logistics.

Financial and Command Enablers
NameFunctionKey DetailsDOBPlace of Birth
Ali Aliakbar AnsariFinancial/logistics nodePassports: Iran, St Kitts, Cyprus; Dubai26 Dec 1968Ghazvin
Ali HoseynitashStrategic commandIRGC BG; head of SNSC strategic dept
Mojtaba HaeriIndustrial oversightMODAFL industrial deputy; AIO/DIO
Nader SaediLegacy threatSun Army / Mersad
Mostafa SadeghiLegacy threatMabna Institute

12Tradecraft & TTPs

The dominant pattern is rapid exploitation of publicly known vulnerabilities (N-day) rather than expensive zero-days.

Common motifs include:

13Closing Assessment

As of early 2026:

For Defenders

This is not just "data theft." It is a blended model of human-centric intrusion, political influence operations, cyber-to-operations effects, and tech-enabled domestic control.

END OF REPORT

IRGC Cyber Ecosystem | Forensic Intelligence Report 2014-2026 | Cloud4o