Intelligence on Iran’s digital operations.
Digital Impact Lab is a Washington-based intelligence operation focused on Iran’s digital operations. We have been doing this work since 2018. We produce research and analysis on the Iranian state’s activities online: its cyber capabilities, its influence networks, its sanctions evasion infrastructure, and the conditions on the networks that connect Iranian society to the wider internet. Our work draws on native Persian-language capability, proprietary technology, and a focus that goes deeper than generalist firms can on this region.
Four domains of Iranian state activity online.
Cyber Operations
Iranian state-aligned threat actors, their infrastructure, and their operations against targets inside and outside the country.
Information Operations
State media ecosystems, IRGC-linked information networks, coordinated inauthentic behavior, and the narratives Tehran promotes online.
Sanctions & Procurement
Front companies, financial evasion, beneficial ownership structures, and the procurement networks that sustain sanctioned activity.
Network Infrastructure
Iranian internet architecture, censorship and surveillance systems, connectivity patterns, and the AI-driven analysis we use to monitor conditions on Iranian networks at scale.
Recent research and analysis.
Iran Can Cut the Internet. It Cannot Keep It Cut
Iran’s 88-day nationwide internet shutdown following February 2026 strikes, the longest ever measured, ended in late May after Communications Minister Sattar Hashemi confirmed roughly 50 percent of national traffic was bypassing official gateways via Starlink, with volume comparable to state-controlled infrastructure. Independent measurement by IPInfo shows Iranian reachable IP space fell to 0.45 percent of baseline in early March 2026, with consumer ISPs reduced to 0.2 to 2.9 percent of normal reachability while state networks held steady. The Iran Blockchain Association estimated daily losses at $23 million to $60 million over 70 days, with cumulative damage projected at $1.7 billion to $4.1 billion, forcing retreat despite factional commitment to permanent disconnection modeled on North Korea.
Read on Digital Impact Lab Substack →Security Alert: Telegram “Session-Grabber” Phishing Adds Fake “Microsoft Teams” Meetings, and Leaves a Traceable Device Fingerprint
CERTFA confirms that a real-time Telegram session-hijacking campaign targeting Iranian journalists and diaspora civil-society figures has evolved to use counterfeit Microsoft Teams meeting lures hosted on disposable Cloudflare Quick Tunnels and the homoglyph domain teiegram[.]site. The operator impersonates trusted contacts (including AI-cloned voice notes), tricks victims into entering their live Telegram login codes and two-step-verification passwords, then relays the credentials to establish a persistent session that bypasses SMS and app-based one-time codes. CERTFA has identified a unique device fingerprint (“teltoone, 1.0, MS Teams, Android, V8 Core”) visible in compromised accounts’ Active Sessions lists, attributed with moderate-to-high confidence to the MOIS-linked Banished Kitten cluster, with the origin traced to 84[.]200[.]24[.]161 (Frankfurt, Germany).
Read on CERTFA Radar →The Let’s Encrypt Clause: Reading a Warranty Without the License
CERTFA documented a consistent pattern of Iranian state-linked threat actors incorporating Let’s Encrypt certificates into offensive operations since 2018, including the 2018 DNS hijacking campaign targeting Lebanese and UAE government infrastructure, the 2019 credential-harvesting operation against 380+ universities in 30 countries, and recent pre-operational staging infrastructure in 2025. OFAC General License D-2, issued September 2022, explicitly authorizes SSL certificate provisioning to Iranian civilian users but does not cover state operations. Let’s Encrypt’s June 2026 subscriber agreement update added a sanctions warranty that, while restating existing legal requirements, failed to reflect the GL D-2 exemption framework governing actual issuance practice to non-government Iranian users.
Read on Digital Impact Lab Substack →