Washington, D.C.

Intelligence on Iran’s digital operations.

Digital Impact Lab is a Washington-based intelligence operation focused on Iran’s digital operations. We have been doing this work since 2018. We produce research and analysis on the Iranian state’s activities online: its cyber capabilities, its influence networks, its sanctions evasion infrastructure, and the conditions on the networks that connect Iranian society to the wider internet. Our work draws on native Persian-language capability, proprietary technology, and a focus that goes deeper than generalist firms can on this region.

Charming Kitten OilRig MuddyWater Pioneer Kitten Imperial Kitten
Latest work

Recent research and analysis.

Digital Impact Lab Substack 2026.07.06
Network Infrastructure

Iran Can Cut the Internet. It Cannot Keep It Cut

Iran’s 88-day nationwide internet shutdown following February 2026 strikes, the longest ever measured, ended in late May after Communications Minister Sattar Hashemi confirmed roughly 50 percent of national traffic was bypassing official gateways via Starlink, with volume comparable to state-controlled infrastructure. Independent measurement by IPInfo shows Iranian reachable IP space fell to 0.45 percent of baseline in early March 2026, with consumer ISPs reduced to 0.2 to 2.9 percent of normal reachability while state networks held steady. The Iran Blockchain Association estimated daily losses at $23 million to $60 million over 70 days, with cumulative damage projected at $1.7 billion to $4.1 billion, forcing retreat despite factional commitment to permanent disconnection modeled on North Korea.

Read on Digital Impact Lab Substack →
CERTFA Radar 2026.07.04
Cyber Operations

Security Alert: Telegram “Session-Grabber” Phishing Adds Fake “Microsoft Teams” Meetings, and Leaves a Traceable Device Fingerprint

CERTFA confirms that a real-time Telegram session-hijacking campaign targeting Iranian journalists and diaspora civil-society figures has evolved to use counterfeit Microsoft Teams meeting lures hosted on disposable Cloudflare Quick Tunnels and the homoglyph domain teiegram[.]site. The operator impersonates trusted contacts (including AI-cloned voice notes), tricks victims into entering their live Telegram login codes and two-step-verification passwords, then relays the credentials to establish a persistent session that bypasses SMS and app-based one-time codes. CERTFA has identified a unique device fingerprint (“teltoone, 1.0, MS Teams, Android, V8 Core”) visible in compromised accounts’ Active Sessions lists, attributed with moderate-to-high confidence to the MOIS-linked Banished Kitten cluster, with the origin traced to 84[.]200[.]24[.]161 (Frankfurt, Germany).

Read on CERTFA Radar →
Digital Impact Lab Substack 2026.06.12
Cyber Operations

The Let’s Encrypt Clause: Reading a Warranty Without the License

CERTFA documented a consistent pattern of Iranian state-linked threat actors incorporating Let’s Encrypt certificates into offensive operations since 2018, including the 2018 DNS hijacking campaign targeting Lebanese and UAE government infrastructure, the 2019 credential-harvesting operation against 380+ universities in 30 countries, and recent pre-operational staging infrastructure in 2025. OFAC General License D-2, issued September 2022, explicitly authorizes SSL certificate provisioning to Iranian civilian users but does not cover state operations. Let’s Encrypt’s June 2026 subscriber agreement update added a sanctions warranty that, while restating existing legal requirements, failed to reflect the GL D-2 exemption framework governing actual issuance practice to non-government Iranian users.

Read on Digital Impact Lab Substack →
Approach

Most analysis of Iran’s digital operations is produced by generalist firms covering many regions, or by academic researchers working at a remove. We focus on a single country and the networks, actors, and infrastructure that constitute its digital presence.

Read our approach