threatintel
actor tracker
Map
IR · Iran

Iran actors

10 tracked

APT33

apt33

Iranian state-sponsored actor with strategic intelligence interest in the global energy supply chain. Long-running password-spray and credential-theft campaigns against aviation and defense industria…

IR · IranAPTModerate confidence
4 aliases4 TTPs1 event

APT34

apt34

Iranian state-sponsored actor publicly assessed to operate on behalf of the Iranian government, with persistent targeting of Middle East government, financial, energy, and telecommunications organiza…

IR · IranAPTModerate confidence
5 aliases4 TTPs1 event

APT35

apt35

Iranian state-sponsored actor associated with the IRGC. Conducts long-term espionage and credential-phishing operations against journalists, dissidents, U.S. and Israeli government targets, and acade…

IR · IranAPTModerate confidence
3 aliases4 TTPs2 events

APT39

apt39

Iranian state-affiliated intrusion set publicly attributed to Rana Intelligence Computing — an MOIS (Ministry of Intelligence and Security) front company sanctioned by the U.S. Treasury OFAC in Septe…

IR · IranAPTHigh confidence
3 aliases4 TTPs1 event

CyberAv3ngers

cyber-avengers

Iranian state-aligned hacktivist persona publicly attributed by the U.S. Treasury OFAC in February 2024 as a front for the IRGC Cyber-Electronic Command. Conducts opportunistic compromise of internet…

IR · IranHacktivistHigh confidence
2 aliases3 TTPs4 events

Handala

handala

Pro-Palestine hacktivist persona operated by the Iranian MOIS-affiliated **Void Manticore** cluster — see the parent actor entry for the full attribution chain. Named for the Naji al-Ali cartoon char…

IR · IranHacktivistModerate confidence
0 aliases4 TTPs1 event

Homeland Justice

homeland-justice

Public-facing hacktivist persona operated by the Iranian MOIS-affiliated Void Manticore cluster, used for the July 2022 destructive intrusion of the Albanian government's central IT infrastructure. T…

IR · IranHacktivistHigh confidence
0 aliases3 TTPs1 event

MuddyWater

muddywater

Iranian state-sponsored actor publicly attributed in 2022 by U.S. Cyber Command to subordinates of the Ministry of Intelligence and Security (MOIS). Conducts espionage and access operations against t…

IR · IranAPTHigh confidence
5 aliases4 TTPs1 event

Pioneer Kitten

pioneer-kitten

Iranian state-affiliated intrusion set publicly attributed by FBI, CISA, and DC3 in joint advisory AA24-241A as connected to the Government of Iran and operating partly through an Iranian IT-services…

IR · IranAPTHigh confidence
5 aliases4 TTPs1 event

Void Manticore

void-manticore

Iranian state-sponsored intrusion set publicly attributed to the Ministry of Intelligence and Security (MOIS), specialised in destructive operations and conducting them under a rotating set of public…

IR · IranAPTModerate confidence
5 aliases4 TTPs3 events