Cyber Operations
We track Iranian state-aligned cyber actors, their infrastructure, and the operations they run against targets inside and outside Iran. Our work informs media coverage and government investigations into Iranian cyber activity.
We document the people, infrastructure, and operations that constitute Iran’s cyber apparatus. The aperture is wide: APT groups linked to the Ministry of Intelligence and the Islamic Revolutionary Guard Corps, contractor networks operating on behalf of state customers, and the infrastructure these actors deploy and reuse over time.
Iranian cyber operations sit inside a broader system of state activity that connects directly to influence operations, sanctions evasion, and the information environment we cover in adjacent focus areas. Understanding any single actor in isolation produces incomplete analysis. We treat the cyber pillar as one face of a system, and our work in this domain is informed by what we see across the others.
Our published research and dossiers in this area have informed coverage at major international media outlets and supported government enforcement and investigative work. The work is cited regularly by peer research organizations and used by security teams in industries with Iran exposure.
Five sub-areas inside the cyber pillar.
Threat Actor Profiling
Specific APT groups, their tooling, targeting patterns, organizational relationships, and evolution over time. We maintain an internal directory of Iranian threat actors that informs our published research.
Infrastructure Analysis
The servers, domains, hosting relationships, and tooling that Iranian actors deploy. Reuse patterns across campaigns. Operational tradecraft observed in the wild.
Contractor Networks
Private companies providing offensive and defensive cyber capabilities to MOIS, IRGC, and other state customers. Personnel, ownership structures, and the financial relationships that sustain them.
Campaign Documentation
Specific operations as they develop. Targets, methods, timing, and the analytical question of why a campaign is running now and what it tells us about state intent.
Attribution Research
Linking observed activity to specific actors with documented methodology. We treat attribution as a discipline. Claims are sourced. Methodology is documented. We treat the claims we publish as ones we will defend.
Our work in cyber draws on Persian-language source networks, our internal directory of Iranian threat actors, and the operational visibility we maintain into Iranian network conditions.
Most analysis of Iranian cyber operations is produced by generalist threat-intelligence firms covering many regions, often with limited Persian-language capability. We work in Persian as a primary research language and maintain source relationships in Iranian-language closed channels that most Western firms cannot reach. This is the single most important factor separating depth from surface in this domain.
Read our full approach →Selected research and analysis on cyber operations.
Security Alert: Telegram “Session-Grabber” Phishing Adds Fake “Microsoft Teams” Meetings, and Leaves a Traceable Device Fingerprint
CERTFA confirms that a real-time Telegram session-hijacking campaign targeting Iranian journalists and diaspora civil-society figures has evolved to use counterfeit Microsoft Teams meeting lures hosted on disposable Cloudflare Quick Tunnels and the homoglyph domain teiegram[.]site. The operator impersonates trusted contacts (including AI-cloned voice notes), tricks victims into entering their live Telegram login codes and two-step-verification passwords, then relays the credentials to establish a persistent session that bypasses SMS and app-based one-time codes. CERTFA has identified a unique device fingerprint (“teltoone, 1.0, MS Teams, Android, V8 Core”) visible in compromised accounts’ Active Sessions lists, attributed with moderate-to-high confidence to the MOIS-linked Banished Kitten cluster, with the origin traced to 84[.]200[.]24[.]161 (Frankfurt, Germany).
Read on CERTFA Radar →The Let’s Encrypt Clause: Reading a Warranty Without the License
CERTFA documented a consistent pattern of Iranian state-linked threat actors incorporating Let’s Encrypt certificates into offensive operations since 2018, including the 2018 DNS hijacking campaign targeting Lebanese and UAE government infrastructure, the 2019 credential-harvesting operation against 380+ universities in 30 countries, and recent pre-operational staging infrastructure in 2025. OFAC General License D-2, issued September 2022, explicitly authorizes SSL certificate provisioning to Iranian civilian users but does not cover state operations. Let’s Encrypt’s June 2026 subscriber agreement update added a sanctions warranty that, while restating existing legal requirements, failed to reflect the GL D-2 exemption framework governing actual issuance practice to non-government Iranian users.
Read on Digital Impact Lab Substack →Security Alert: Telegram & WhatsApp “Session-Grabber” Phishing Targeting Iranian Journalists
CERTFA documents a real-time session-hijacking campaign targeting Iranian journalists and civil-society figures using a homoglyph domain (teiegram[.]site, capital “I” for lowercase “l”) to relay live Telegram login codes and harvest 2FA cloud passwords. The operator delivers lures via WhatsApp impersonating known contacts with a “new number,” proposing collaboration or interviews, then relays victims’ one-time codes to Telegram’s authentication system to seize accounts within seconds. CERTFA assesses with moderate-to-high confidence that the operation is conducted by the MOIS-linked Banished Kitten cluster (Storm-0842 / “Dune”), operated via contractor Parsian Afzar Rayan Borna, based on victimology, tradecraft, and native Persian social engineering.
Read on CERTFA Radar →The cyber pillar sits alongside three other domains of Iranian state activity online.
Information Operations
State media ecosystems, IRGC-linked information networks, coordinated inauthentic behavior, and the narratives Tehran promotes online.
Sanctions & Procurement
Front companies, financial evasion, beneficial ownership structures, and the procurement networks that sustain sanctioned activity.
Network Infrastructure
Iranian internet architecture, censorship and surveillance systems, connectivity patterns, and the AI-driven analysis we use to monitor conditions on Iranian networks at scale.