The Islamic Revolutionary Guard Corps (IRGC), also referred to as the Iranian Revolutionary Guards and IRGC, is an Iranian state military and intelligence organization. The content attributes to the IRGC a broad threat profile spanning maritime coercion and attacks in and around the Strait of Hormuz, cyber and cyber-enabled activity, overseas targeting, online propaganda, and sanctions-evasion-linked financial activity. The IRGC Quds Force is specifically mentioned as a component involved in some of this activity. In the maritime domain, the content repeatedly attributes vessel strikes, drone attacks, gunboat harassment, VHF transit warnings, corridor enforcement, and vessel seizures to the IRGC. Reported activity includes attacks on commercial shipping, including LNG carriers, tankers, bulk carriers, and container ships; operation of an IRGC-controlled northern transit corridor near Larak Island; use of high-speed craft and gunboats; direct warnings to vessel masters; and escalation from deterrence and warning to direct engagement and vessel seizure. The content also attributes attacks on specific vessels and infrastructure to the IRGC, including strikes on Qatari LNG assets, the drone strike on MSC ISHYKA in Bahrain, firing on SANMAR HERALD, attacks affecting HMM NAMU and BARAKAH, and broader kinetic enforcement across previously safer southern transit lanes. In cyber and cyber-enabled activity, the content states that IRGC-affiliated cyber actors exploited PLCs in multiple sectors, including U.S. water and wastewater systems facilities. It also states that Iranian Revolutionary Guards intelligence initiated a phishing campaign targeting individuals abroad involved in Iran-related activities, specifically targeting WhatsApp users. The content further notes warnings from U.S., UK, and European agencies about activity attributed to the IRGC involving compromise of users of commercial messaging platforms by bypassing account security rather than breaking encryption. The content also states that Iran’s military and intelligence agencies, particularly the IRGC, have almost certainly continued efforts to recruit and incite overseas threat actors to conduct targeted attacks and assassinations against high-profile U.S. politicians and Iranian dissidents on U.S. soil. In Latin America, the content says the IRGC, particularly through its Quds Force, has been expanding its presence and cooperating with local criminal networks such as drug cartels to fund operations. Financially, the content links the IRGC to cryptocurrency-based sanctions-evasion and illicit finance ecosystems. TRM analysis cited in the content found exposure between the A7 network and the IRGC and states that one A7 address received more than USD 65 million in direct transfers from an address attributed to the IRGC. The content also references IRGC-linked and state-aligned use of domestic Iranian exchanges and counterparties for sanctions evasion, proxy financing, and illicit trade. The content further describes IRGC online propaganda, recruitment, and fundraising infrastructure. Europol-led action targeted 14,200 IRGC-linked posts and links across social media, streaming services, blogs, and standalone websites. The material reportedly included multilingual propaganda, speeches, AI-generated videos glorifying the IRGC, and content tied to aligned groups including Hezbollah, Ansar Allah, Hamas, PIJ, and HAYI. The IRGC’s main X account was reportedly withheld in the EU following this action. The content also attributes public strike threats against U.S. technology and finance companies to the IRGC and states that the IRGC has been linked in reporting to strikes against AWS sites in the Middle East. Known aliases in the content are Iranian Revolutionary Guards, iranian_revolutionary_guards, and Islamic Revolutionary Guard Corps. The Quds Force is identified as a relevant IRGC component.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting kinetic maritime attacks and coercive corridor enforcement in the Strait of Hormuz, including repeated strikes on Qatari LNG assets and pressure on commercial shipping lanes.
Linked to A7 through direct cryptocurrency transfers and broader sanctioned financial facilitation tied to Iranian oil sales and regional proxy support.
Iranian military/security force activity in and around the Strait of Hormuz, including a reported drone strike, persistent small-craft presence, and possible boarding-preparation activity near a commercial vessel.
Uses online platforms to spread propaganda, recruit supporters, raise funds, disseminate multilingual extremist content, leverage hosting providers across multiple jurisdictions, and use cryptocurrency transactions to sustain and amplify online operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.