Skip to main content

Iranian Cyber Threat Actors

Live Monitoring

IRGC & MOIS Operatives

IRGC • MOIS • APT35 • RANA

January 2026: These actors are linked to the ongoing internet blackout and GPS jamming affecting 50,000+ Starlink terminals.

IRGC Cyber Ecosystem (2014–2026)

Forensic map of IRGC offensive cyber: contractor model, corporate fronts, operators, and cyber-kinetic convergence.

IRGC Cyber Dossier (2024–2026)

Full intelligence dossier on IRGC/MOIS cyber-kinetic convergence, Department 40 documents, and transnational repression networks.

Cyber Adversary PII Deep Dive

Identity resolution of Iranian state-sponsored cyber adversaries: Mabna Institute, Rana Intelligence (APT39), ITSecTeam, Mersad, and Emennet Pasargad.

Filter by Available Data

121
Threat Actors
81
OFAC Sanctioned
43
DOJ Indicted
25
Organizations
HIGH
Mohammad Najafloo

Mohammad Najafloo

محمد نجف لو

Former senior official, Department 40 (IRGC external cyber operations)

IRGC • APT35
HIGH

Mohammad Reza Jafari Bandar-Abadi

محمدرضا جعفری بندرآبادی

Malware developer targeting dissidents - APT39/Chafer operative

MOIS • RANA
OFAC
MEDIUM
Navid Nilchi

Navid Nilchi

Cyberbannews operative, Shahid Kaveh cyber unit

IRGC • MOIS
CRITICAL
Niloofar Bagheri

Niloofar Bagheri

نیلوفر باقری

IRGC Commander - Head of Sister's Team (Aqiq/واحد خواهران) within Department 40

IRGC • APT35
MEDIUM

Mahmoud Mehri

محمود مهری

Social engineering and data collection specialist - APT39/Chafer operative

MOIS • RANA
OFAC
MEDIUM

Mahdi Hejabi

مهدی حجابی

Network security operations specialist - APT39/Chafer operative

MOIS • RANA
OFAC
MEDIUM

Abolfazl Hosseinpour Davoodi

ابوالفضل حسین‌پور داوودی

Social engineering operative - APT39/Chafer hacking expert

MOIS • RANA
OFAC
MEDIUM
Mohammad Reza Basharat

Mohammad Reza Basharat

محمدرضا بشارت

Network security and penetration testing specialist - APT39/Chafer

MOIS • RANA
OFAC
HIGH
Seyyeed Hossein Raja

Seyyeed Hossein Raja

Senior network/security specialist at DSPRI

IRGC
HIGH

Mehrnush Rezali

APT35/Charming Kitten operative, Sisters Team member

IRGC • APT35
HIGH
Nader Saedi

Nader Saedi

نادر ساعدی

DDoS attack expert, Mersad employee, Former Sun Army member

IRGC
DOJFBI
CRITICAL
Mostafa Sadeghi

Mostafa Sadeghi

مصطفی صادقی

Hacker for Mabna Institute / Silent Librarian APT - Compromised 1,000+ university professor accounts

IRGC
OFACDOJFBI
CRITICAL
Gholamreza Rafatnejad

Gholamreza Rafatnejad

غلامرضا رفعت‌نژاد

Founding member of Mabna Institute - Organized the hacking campaign

IRGC
OFACDOJFBI
CRITICAL
Ehsan Mohammadi

Ehsan Mohammadi

احسان محمدی

Founding member of Mabna Institute - Coordinated university breaches

IRGC
OFACDOJFBI
HIGH
Abdollah Karima

Abdollah Karima

عبدالله کریما

Operator of Megapaper.ir and Gigapaper.ir - Sold stolen academic data

IRGC
OFACDOJFBI
HIGH
Seyed Ali Mirkarimi

Seyed Ali Mirkarimi

سید علی میرکریمی

Mabna Institute contractor - Spearphishing specialist

IRGC
OFACDOJFBI
HIGH
Sajjad Tahmasebi

Sajjad Tahmasebi

سجاد طهماسبی

Mabna Institute contractor - Network surveillance specialist

IRGC
OFACDOJFBI
MEDIUM
Roozbeh Sabahi

Roozbeh Sabahi

روزبه صباحی

Mabna Institute contractor - Credential organization

IRGC
OFACDOJFBI
MEDIUM
Mohammed Reza Sabahi

Mohammed Reza Sabahi

محمدرضا صباحی

Mabna Institute contractor - Created professor targeting lists

IRGC
OFACDOJFBI
MEDIUM
Abuzar Gohari Moqadam

Abuzar Gohari Moqadam

ابوذر گوهری مقدم

Iranian professor - Exchanged stolen credentials with Mabna

IRGC
OFACDOJFBI
HIGH

Gholamreza Radmard Iranagh

غلامرضا رادمرد ایراناق

RANA Intelligence programmer - APT39/Chafer operative

MOIS • RANA
OFAC
HIGH
Mohsen Raeisi Nafchi

Mohsen Raeisi Nafchi

محسن رئیسی نافچی

RANA Intelligence hacking expert - APT39/Chafer

MOIS • RANA
OFAC
HIGH
Seyed Mohammad Ghaffariananberan

Seyed Mohammad Ghaffariananberan

سید محمد غفاریان

RANA Intelligence manager - APT39/Chafer

MOIS • RANA
OFAC
MEDIUM

Maysam Jalali

میثم جلالی

RANA Intelligence programmer - APT39/Chafer

MOIS • RANA
OFAC
MEDIUM

Mohsen Noori

محسن نوری

RANA Intelligence operative - APT39/Chafer

MOIS • RANA
OFAC
MEDIUM

Mostafa Sedaghati

مصطفی صداقتی

RANA Intelligence operative - APT39/Chafer

MOIS • RANA
OFAC
CRITICAL
Abbas Rahrovi

Abbas Rahrovi

عباس رهروی

Commander of Department 40 - IRGC Intelligence Division 1500 cyber operations chief

IRGC • APT35
HIGH

Mohammad Erfan Hamidi Aref

محمد عرفان حمیدی عارف

Department 40 - Infrastructure operations lead (Brothers Team/Pelak1)

IRGC • APT35
HIGH
Mahdi Sharifi

Mahdi Sharifi

مهدی شریفی

Department 40 - Karaj Hacker Team (P8) Leader - Led Dubai Police breach

IRGC • APT35
HIGH
Vahid Molawi

Vahid Molawi

وحید مولوی

Department 40 - Karaj Hacker Team (P8) core operator

IRGC • APT35
HIGH
Esmaeil Heydari

Esmaeil Heydari

اسماعیل حیدری

Department 40 - Karaj Hacker Team (P8) core operator

IRGC • APT35
MEDIUM

Alireza Feizi

علیرضا فیضی

Department 40 - Karaj Hacker Team (P8) hacker

IRGC • APT35
MEDIUM
Amirhossein Aminnezhad

Amirhossein Aminnezhad

امیرحسین امین‌نژاد

Department 40 - Karaj Hacker Team (P8) hacker

IRGC • APT35
MEDIUM

Amirhossein Inanloo

امیرحسین اینانلو

Department 40 - Karaj Hacker Team (P8) hacker

IRGC • APT35
HIGH

Manoochehr Vosoughi Nayeri

منوچهر وثوقی نایری

IRGC Intelligence Organization authority - Front company official

IRGC • APT35
MEDIUM

Davood Ghanbari

داوود قنبری

Department 40 - Brothers Team (Pelak1) logistics

IRGC • APT35
CRITICAL
Masoud Jalili

Masoud Jalili

مسعود جلیلی

IRGC/Basij cyber operative - 2024 US Election targeted hacking operation

IRGC
OFACDOJFBI
CRITICAL
Seyyed Ali Aghamiri

Seyyed Ali Aghamiri

سید علی آقامیری

IRGC/Basij cyber operative - 2024 US Election targeted hacking operation

IRGC
DOJFBI
CRITICAL
Yasar Balaghi

Yasar Balaghi

یاسر بلاغی

IRGC/Basij cyber operative - 2024 US Election targeted hacking operation (alias: Wool3n.H4t)

IRGC
DOJFBI
CRITICAL

Ahmad Khazai

احمد خزایی

MOIS Deputy Head of Counterintelligence - Robert Levinson kidnapping

MOIS
OFAC
CRITICAL

Mohammad Baseri

محمد باصری

MOIS Head of US Team - Robert Levinson kidnapping

MOIS
OFAC
CRITICAL

Ali Larijani

علی لاریجانی

Secretary of Supreme National Security Council - Coordinator of Protest Crackdown

IRGC
OFAC
HIGH

Mohammad Reza Hashemifar

محمدرضا هاشمی‌فر

Commander of Law Enforcement Forces - Lorestan Province

IRGC
OFAC
HIGH

Nematollah Bagheri

نعمت‌الله باقری

IRGC Commander - Lorestan Province

IRGC
OFAC
HIGH

Azizollah Maleki

عزیزالله ملکی

LEF Commander - Fars Province

IRGC
OFAC
HIGH

Yadollah Buali

یدالله بوعلی

IRGC Commander - Fars Province

IRGC
OFAC
HIGH

Mehdi Rashno

مهدی رشنو

Board Member - Nikan Pezhvak Aria Kish Company (Shadow Banking)

IRGC
OFAC
HIGH

Bashir Abbaspour Qomi

بشیر عباسپور قمی

Board Member - Nikan Pezhvak Aria Kish Company (Shadow Banking)

IRGC
OFAC
HIGH

Hamid Reza Khamer

حمیدرضا خامر

Board Member - Nikan Pezhvak Aria Kish Company (Shadow Banking)

IRGC
OFAC
HIGH

Masoud Mahdavi Ardakani

مسعود مهدوی اردکانی

Chairman - Tejarat Hermes Energy Qeshm (Sanctions Evasion)

IRGC
OFAC
HIGH

Masoud Shamani

مسعود شامانی

Director - Tejarat Hermes Energy Qeshm (Sanctions Evasion)

IRGC
OFAC
HIGH

Akbar Givari

اکبر گیواری

Vice Chairman - Tejarat Hermes Energy Qeshm (Sanctions Evasion)

IRGC
OFAC
CRITICAL

Mohammad Amin Aghamiri

محمدامین آقامیری

Architect of Absolute Digital Isolation - 2026 Internet Blackout

IRGC
CRITICAL

Mehdi SeifAbadi

مهدی سیف‌آبادی

Manager of Infrastructure Security Unit - Internet Shutdown Operations

IRGC
CRITICAL

Ali Hakim-Javadi

علی حکیم‌جوادی

Former Head of IT Organization - Architect of New Filtering Model

IRGC
HIGH

Mohammad Hossein Madadi

محمدحسین مددی

IT and Network Infrastructure Operative

IRGC
CRITICAL

Eisa Zarepour

عیسی زارع‌پور

Minister of Communications - Internet Shutdown Coordinator

IRGC
OFAC
CRITICAL

Ahmad Vahidi

احمد وحیدی

Minister of Interior - Oversees Law Enforcement Forces

IRGC
OFAC
HIGH

Hossein Sajedinia

حسین ساجدی‌نیا

Deputy Operations Commander - Law Enforcement Forces

IRGC
OFAC
HIGH

Yadollah Javani

یدالله جوانی

Deputy Political Commander - IRGC

IRGC
OFAC
HIGH

Vahid Mohammad Naser Majid

وحید محمد ناصر مجید

Head of Iranian Cyber Police (FATA)

IRGC
OFAC
HIGH

Hossein Nejat

حسین نژات

IRGC Commander - Head of Sarallah (Tehran Security)

IRGC
OFAC
HIGH

Hossein Rahimi

حسین رحیمی

Law Enforcement Forces Police Chief - Tehran

IRGC
OFAC
HIGH
Ahmad Fathi

Ahmad Fathi

احمد فتحی

ITSecTeam Leader - Managed DDoS infrastructure against US financial sector

IRGC
DOJFBI
CRITICAL
Hamid Firoozi

Hamid Firoozi

حمید فیروزی

ITSecTeam - Bowman Dam SCADA infrastructure attacker

IRGC
DOJFBI
HIGH
Amin Shokohi

Amin Shokohi

امین شکوهی

ITSecTeam - Botnet developer and DDoS specialist

IRGC
DOJFBI
HIGH
Sadegh Ahmadzadegan

Sadegh Ahmadzadegan

صادق احمدزادگان

Mersad Co-Founder (alias: Nitr0jen26) - NASA and Sun Army hacker

IRGC
DOJFBI
HIGH
Omid Ghaffarinia

Omid Ghaffarinia

امید غفاری‌نیا

Mersad Co-Founder (alias: PLuS) - NASA and Sun Army hacker

IRGC
DOJFBI
HIGH
Sina Keissar

Sina Keissar

سینا کیسار

ITSecTeam/Mersad - DDoS attack operator

IRGC
DOJFBI
CRITICAL
Hamid Homayunfal

Hamid Homayunfal

حمید همایون‌فال

IRGC Cyber-Electronic Command (CEC) - Critical Infrastructure Attacks

IRGC
OFAC
CRITICAL
Hamid Reza Lashgarian

Hamid Reza Lashgarian

حمیدرضا لشگریان

Head of IRGC Cyber-Electronic Command (CEC) / Commander in IRGC-Quds Force

IRGC
OFAC
HIGH

Mahdi Lashgarian

مهدی لشگریان

Senior Official, IRGC-CEC / Leader of CyberAv3ngers

IRGC
OFAC
HIGH

Milad Mansuri

میلاد منصوری

IRGC Cyber-Electronic Command (CEC) - Cyber Operations

IRGC
OFAC
HIGH

Mohammad Bagher Shirinkar

محمدباقر شیرینکار

Leader/overseer of Shahid Shushtari (formerly Emennet Pasargad) - IRGC-CEC

IRGC
OFAC
HIGH

Aliakbar Rashidi-Barjini

علی‌اکبر رشیدی بارجینی

Iranian cyber actor - Malicious cyber activities

IRGC
OFAC
HIGH

Mohammad Shakeri Ashtijeh

محمد شاکری آشتیجه

Iranian cyber actor - Malicious cyber activities

IRGC
OFAC
HIGH
Ahmad Khatibi Aghda

Ahmad Khatibi Aghda

احمد خطیبی آقدا

IRGC-affiliated ransomware operator - CEO of Afkar System Yazd Company

IRGC
OFACDOJFBI
HIGH
Hossein Mohammad Harooni

Hossein Mohammad Harooni

حسین محمد هارونی

IRGC cyber operative - Infrastructure and server procurement specialist

IRGC
OFACDOJFBI
HIGH
Reza Kazemifar Rahman

Reza Kazemifar Rahman

رضا کاظمیفر رحمان

IRGC cyber operative - Malware developer and tools tester (IRGC EWCD 2014-2020)

IRGC
OFACDOJFBI
HIGH
Komeil Baradaran Salmani

Komeil Baradaran Salmani

کمیل برادران سلمانی

IRGC cyber operative - Tools testing and quality assurance

IRGC
OFACDOJFBI
HIGH
Alireza Shafie Nasab

Alireza Shafie Nasab

علیرضا شفیعی نسب

IRGC cyber operative - Social engineering infrastructure specialist

IRGC
OFACDOJFBI
CRITICAL

Said Pourkarim Arabi

سعید پورکریم عربی

IRGC Intelligence Officer - Ringleader of aerospace hacking campaign

IRGC
DOJFBI
HIGH
Mohammad Reza Espargham

Mohammad Reza Espargham

محمدرضا اسپرغم

IRGC cyber operative - Malware developer (creator of VBScan tool) / OWASP Foundation member

IRGC
DOJFBI
HIGH
Mohammad Bayati

Mohammad Bayati

محمد بیاتی

IRGC cyber operative - Malware support and infrastructure

IRGC
DOJFBI
HIGH
Mansour Ahmadi

Mansour Ahmadi

منصور احمدی

IRGC-affiliated ransomware operator - Owner of Najee Technology (aliases: Masoud Akbari, Parsa Unsi)

IRGC
OFACDOJFBI
HIGH
Amir Hossein Nickaein Ravari

Amir Hossein Nickaein Ravari

امیرحسین نیکائین راوری

IRGC-affiliated ransomware operator (aliases: Amir Hossein Nikaeen, Amir Hosein Nika'in)

IRGC
OFACDOJFBI
HIGH
Seyyed Mohammad Hosein Musa Kazemi

Seyyed Mohammad Hosein Musa Kazemi

سید محمدحسین موسی کاظمی

Iranian hacker - Emennet Pasargad operative, 2020 election interference (alias: Hosein Zamani)

IRGC • MOIS
OFACDOJ
HIGH
Sajjad Kashian

Sajjad Kashian

سجاد کاشیان

Iranian hacker - Emennet Pasargad operative, 2020 election interference (alias: Kiarash Nabavi)

IRGC • MOIS
OFACDOJ
MEDIUM
Behzad Mohammadzadeh

Behzad Mohammadzadeh

بهزاد محمدزاده

Website defacer - Soleimani retaliation attacks (alias: Mrb3hz4d)

IRGC
DOJFBI
HIGH
Mohammad Mehdi Farhadi Ramin

Mohammad Mehdi Farhadi Ramin

محمد مهدی فرهادی رامین

Cyber theft and state-sponsored espionage specialist (alias: Mehdi Mahdavi, "Sejeal")

IRGC
DOJFBI
HIGH
Hooman Heidarian

Hooman Heidarian

هومان حیدریان

Cyber theft partner - State-sponsored hacker (alias: "neo", "Sejeal")

IRGC
DOJFBI
HIGH
Behzad Mesri

Behzad Mesri

بهزاد مصری

IRGC cyber operative - HBO hacker, Monica Witt case operative

IRGC
DOJFBI
HIGH
Mojtaba Masoumpour

Mojtaba Masoumpour

مجتبی معصوم‌پور

IRGC cyber operative - Monica Witt espionage case

IRGC
DOJFBI
HIGH
Hossein Parvar

Hossein Parvar

حسین پروار

IRGC cyber operative - Monica Witt espionage case

IRGC
DOJFBI
HIGH
Mohamad Paryar

Mohamad Paryar

محمد پریار

IRGC cyber operative - Monica Witt espionage case

IRGC
DOJFBI
HIGH
Ali Mahdavian

Ali Mahdavian

علی مهدویان

Emennet Pasargad employee - 2024 US election interference (alias: HADIAN, Ali)

MOIS
OFAC
HIGH

Sayyed Mehdi Rahimi Hajjiabadi

سید مهدی رحیمی حاجی آبادی

Emennet Pasargad employee - 2024 US election interference

MOIS
OFAC
HIGH
Fatemeh Sadeghi

Fatemeh Sadeghi

فاطمه صادقی

Emennet Pasargad employee - 2024 US election interference

MOIS
OFAC
HIGH

Elaheh Yazdi

الهه یزدی

Emennet Pasargad employee - 2024 US election interference

MOIS
OFAC
HIGH

Mohammad Hosein Abdolrahimi

محمد حسین عبدالرحیمی

Emennet Pasargad employee - 2024 US election interference

MOIS
OFAC
HIGH

Rahmatollah Askarizadeh

رحمت‌الله عسکری‌زاده

Emennet Pasargad employee - 2024 US election interference

MOIS
OFAC
HIGH
Reza Mohammad Amin Saberian

Reza Mohammad Amin Saberian

رضا محمد امین صابریان

IRGC Cyber-Electronic Command (CEC) official

IRGC
OFAC
HIGH

Mohammad Agha Ahmadi

محمد آقااحمدی

IRGC-affiliated ransomware operator

IRGC
OFAC
HIGH

Mostafa Haji Hosseini

مصطفی حاجی حسینی

IRGC-affiliated ransomware operator

IRGC
OFAC
CRITICAL

Faramarz Shahi Savandi

فرامرز شاهی ساوندی

SamSam ransomware developer and operator

IRGC
OFACDOJFBI
CRITICAL

Mohammad Mehdi Shah Mansouri

محمد مهدی شاه منصوری

SamSam ransomware developer and operator

IRGC
OFACDOJFBI
HIGH

Manuchehr Akbari

منوچهر اکبری

Shahid Hemmat hacking group - IRGC-CEC operative

IRGC
OFAC
HIGH
Amir Hosein Hoseini

Amir Hosein Hoseini

امیرحسین حسینی

Shahid Hemmat hacking group - IRGC-CEC operative

IRGC
OFAC
HIGH

Mohammad Hosein Moradi

محمد حسین مرادی

Shahid Hemmat hacking group - IRGC-CEC operative

IRGC
OFAC
HIGH
Mohammad Reza Rafatinezhad

Mohammad Reza Rafatinezhad

محمدرضا رفعتی‌نژاد

Shahid Hemmat hacking group - IRGC-CEC operative

IRGC
OFAC
HIGH
Fatemeh Sedighian Kashi

Fatemeh Sedighian Kashi

فاطمه صدیقیان کاشی

Shahid Shushtari operative - Long-time IRGC-CEC front company employee

IRGC
OFACDOJ
HIGH

Behrouz Parsarad

بهروز پارسارد

Nemesis Market dark web founder and operator - Drug trafficking and money laundering

IRGC
OFACDOJ
HIGH
Reza Mohammad Amin Saberian

Reza Mohammad Amin Saberian

رضا محمد امین صابریان

Senior Official, IRGC-CEC - Strategic and technical guidance

IRGC
OFAC
CRITICAL
Yahya Hosseini Panjaki

Yahya Hosseini Panjaki

یحیی حسینی پنجکی

Deputy for Domestic Security, MOIS - Commands Handala/Banished Kitten

MOIS
OFACFBI
MEDIUM
Ali Bermoudeh

Ali Bermoudeh

علی برموده

MOIS Handala Hack Team operator - Amateur hacker

MOIS
HIGH
Morteza Aftabifar

Morteza Aftabifar

مرتضی آفتابی‌فر

MOIS Handler - Intermediary between command and operators

MOIS
CRITICAL
Naji Ibrahim Sharifi-Zindashti

Naji Ibrahim Sharifi-Zindashti

ناجی ابراهیم شریفی زین‌دشتی

Criminal Kingpin / MOIS Asset - Leads assassination network

MOIS
OFACDOJ
HIGH

Nihat Abdul Kadir Asan

نهاد عبدالقادر آسان

Zindashti Network Logistical Planner - Recruits gunmen

MOIS
OFAC
HIGH

Ekrem Abdulkerym Oztunc

اکرم عبدالکریم اوزتونچ

Zindashti Network Lieutenant - Nephew and key operative

MOIS
OFAC
HIGH

Shahram Ali Reza Tamarzadeh Zavieh Jakki

شهرام علیرضا تامرزاده زاویه جکی

Zindashti Network Associate - Brother-in-law

MOIS
OFAC
HIGH
Ali Aliakbar Ansari

Ali Aliakbar Ansari

علی علی‌اکبر انصاری

Financial Facilitator - IRGC money laundering through real estate

IRGC
OFAC

Organizations

APT35 / Charming Kitten

Aliases: Phosphorus, Fresh Feline, NewsBeef, Ajax Security Team

Parent Organization: IRGC Intelligence Organization

State-sponsored cyber espionage group targeting journalists, activists, academics, and government officials.

RANA Intelligence Organization

Aliases: RANA, APT39, Chafer

Parent Organization: MOIS (Ministry of Intelligence)

Front company for MOIS conducting cyber operations against Iranian dissidents and foreign targets.

Department 40

Aliases: Division 1500, IRGC External Cyber Operations

Parent Organization: IRGC Intelligence Organization

External cyber operations unit conducting offensive operations against regional targets. Operates under 2017 Iranian legislation designating US military as "terrorists." Employs distributed model contracting darknet hacker-for-hire services and collaborating with proxy groups (Hezbollah, Iraqi militias, Houthi cyber units). Uses IranInfo Marketplace for data sales. Research indicates OSINT vulnerabilities in operator security.

Mabna Institute

Aliases: Silent Librarian, COBALT DICKENS, TA407, Yellow Nabu, G0122

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

Organization conducting massive credential theft campaign against 320+ universities worldwide. Stole 31+ terabytes of academic data. Operated Megapaper.ir and Gigapaper.ir for selling stolen research. 9 members indicted by DOJ February 2018, OFAC sanctioned March 2018.

APT39 / Chafer

Aliases: Remix Kitten, COBALT HICKMAN, Radio Serpens, ITG07

Parent Organization: MOIS (Ministry of Intelligence)

Iranian cyber espionage group operating through RANA Intelligence Computing Company. Targets travel sector, telecommunications, and Iranian dissidents across 30+ countries. 45 members sanctioned by OFAC September 2020. Deployed 8 distinct malware families.

IRGC Basij Cyber Unit

Aliases: Basij Resistance Force Cyber

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

Paramilitary cyber unit responsible for 2024 US Presidential Election targeted hacking operation. 3 members indicted September 2024, $10M rewards offered. Targets US government officials, campaigns, journalists, and think tanks.

Kashef Surveillance Platform

Parent Organization: Department 40 / IRGC Intelligence

Database system built by Department 40 to track dissidents through mobile phone records, travel data, and location tracking. Obtained in November 2025. Used to map connections between targets for assassination operations.

Infrastructure Security Unit

Aliases: Vahde Amniat Zirsakhtha

Parent Organization: IRGC / Supreme National Security Council

Central hub for decision-making on internet control in Iran. Managed by Mehdi SeifAbadi and Mohammad Amin Aghamiri. Orchestrated the January 2026 "Absolute Digital Isolation" strategy - the most severe internet shutdown in Iran history, blocking all international connectivity during the massacre of 16,500+ protesters.

Law Enforcement Command (LEF)

Aliases: NAJA, FARAJA, Police Force

Parent Organization: Ministry of Interior

Iranian national police force responsible for internal security and protest suppression. Deployed against protesters in 2022 Mahsa Amini and 2026 economic protests. Commands include Tehran Police Chief Hossein Rahimi and provincial commanders sanctioned by OFAC.

Supreme National Security Council (SNSC)

Aliases: Showra-ye Aali-ye Amniyat-e Melli

Parent Organization: Office of Supreme Leader

Iran highest national security and foreign policy decision-making body. Secretary Ali Larijani sanctioned January 2026 for coordinating violent crackdown on protesters on behalf of Supreme Leader Khamenei. Authorized use of lethal force against demonstrators.

Sarallah

Aliases: IRGC Tehran Security

Parent Organization: IRGC

IRGC security apparatus responsible for Tehran. Commander Hossein Nejat sanctioned October 2022. Handles capital security operations and protest suppression in Tehran metropolitan area.

Iranian Cyber Police (FATA)

Aliases: Cyber Police, Police Fata

Parent Organization: Law Enforcement Command

Iranian cyber police unit responsible for monitoring online dissent, targeting activists and journalists, and enforcing internet restrictions. Head Vahid Mohammad Naser Majid sanctioned October 2022.

Yaftar

Parent Organization: IRGC Security Contractors

Security contractor designing Starlink traffic detection systems. Part of infrastructure enabling 2026 internet blackout. Developing technology to detect and block satellite internet access.

Doran Group

Parent Organization: IRGC Security Contractors

Security contractor developing Deep Packet Inspection (DPI) updates for internet surveillance and blocking. Provides technical capabilities for internet censorship infrastructure.

MuddyWater

Aliases: MERCURY, Static Kitten, Seedworm, TEMP.Zagros, MuddyC2Go

Parent Organization: MOIS (Ministry of Intelligence)

Iranian cyber espionage group using MuddyC2Go command and control infrastructure. Employs PhonyC2 framework and N-able Advanced Monitoring Agent for dual-use operations. Deploys custom malware and legitimate admin tools for persistence.

IranInfo Marketplace

Aliases: iranInfo

Parent Organization: IRGC-affiliated Dark Web

Dark web marketplace for Iranian threat actor data sales. SessionApp ID: 05872c824ee1b62e81b7c661ffb64e4424f3b7c7d5b66d65568386da9ff6266755. Bitcoin wallet: bc1qe46dj38ge9nk6fnmtku2dcdgfeepgprmvzttnt. Facilitates IRGC data transactions.

HACKERSTARS

Aliases: Darknet Hacker Marketplace

Parent Organization: Tor Hidden Service

Verified hacker-for-hire marketplace with escrow services (hsssfzzzxboe66mtswcrhxpzlmiejv246pun3ttasg3x4y6xayjag5id.onion). Known verified hackers: N3gr0, Intruder, DigitalKiller, BlackChimp, SilentRoot (99% success), Baloo, KimHack, Ultrum, Joga3, Z3r0Trac3, AntiBot, Ragnazar. Pricing: BTC ~$90,970, ETH ~$3,115, XMR ~$460.

Iranian Darknet Hacker Ecosystem

Aliases: Shadow Hacker, Pr0Hacker, Find a Hacker (FaH), BlackHats

Parent Organization: Tor Hidden Services

Network of hacker-for-hire services potentially leveraged by IRGC for deniable operations. Shadow Hacker (shadowhckr@proton.me, OSWE credentials). Pr0Hacker (active since 2005). Find a Hacker (operational since 2013). FraudGPT AI tool advertised. Services offer email/social media hacking, DDoS, database extraction with escrow protection.

Mehrsam Andisheh Saz Nik (MASN)

Aliases: MASN

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

IRGC front company used in multi-year cyber campaign (2016-2021) targeting US defense contractors, Treasury Department, and State Department. Four operatives indicted April 2024: Hossein Harooni, Reza Kazemifar, Komeil Baradaran Salmani, Alireza Shafie Nasab.

Dadeh Afzar Arman (DAA)

Aliases: DAA

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

IRGC front company partnered with MASN for cyber operations. Exploited over 200,000 victim accounts across US government and private sector. Indicted April 2024 by DOJ.

Najee Technology Hooshmand Fater LLC

Aliases: Najee Technology, Najee

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

IRGC-affiliated ransomware operator. Owner Mansour Ahmadi indicted September 2022. Attacked US critical infrastructure including healthcare, transportation, utilities. Used ransomware-style extortion against hundreds of victims in US, UK, Israel.

Afkar System Yazd Company

Aliases: Afkar System, Afkar

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

IRGC-affiliated company involved in ransomware operations. Ahmad Khatibi Aghda served as managing director. Indicted September 2022 for attacks on critical infrastructure.

Emennet Pasargad

Aliases: Net Peygard Samavat Company

Parent Organization: IRGC / MOIS

Iranian government cybersecurity contractor responsible for 2020 US election interference. Operatives Seyyed Mohammad Hosein Musa Kazemi and Sajjad Kashian indicted November 2021. Obtained confidential voter data on 100,000+ US voters, sent threatening voter intimidation emails.

Cognitive Design Production Center (CDPC)

Aliases: CDPC, مرکز تولید طراحی شناختی

Parent Organization: IRGC (Islamic Revolutionary Guard Corps)

IRGC-affiliated entity designated December 2024 by Treasury for supporting Iranian cyber operations and disinformation campaigns. Involved in producing cognitive warfare content and psychological operations targeting Western audiences.

Nemesis Market

Aliases: Nemesis Darknet Market

Parent Organization: Iran-based Dark Web

Dark web marketplace operated by Behrouz Parsarad from Iran (March 2021 - April 2025). 150,000+ users, 400,000+ orders, $30 million in drug sales including fentanyl. Seized by FBI/DEA Operation Dark Night April 2025.

Iranian Cyber Threat Actors Database | IRGC/MOIS Threat Intel | January 2026 | پایگاه داده تهدیدات سایبری ایران | Cloud4o