Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors

iranian_state_sponsored_threat_actors

Also known asIranian State-Sponsored Threat Actors

Iranian state-sponsored threat actors are engaged in a range of cyber operations including espionage, hack-and-leak, and destructive campaigns, with a focus on targets in Europe, the United States, Israel, and Ukraine. These actors often masquerade as hacktivists to obscure their state affiliation and have been observed leveraging AI and large language models (LLMs) for cyber operations such as phishing, reconnaissance, and online deception. Their campaigns are frequently driven by geopolitical conflicts, particularly those involving Israel and Hamas, and are known to target government, defense, infrastructure, and critical sectors. Iranian actors have also been reported to use AI to automate attacks, generate fake online content, and conduct disinformation campaigns. They are part of a broader ecosystem of state-sponsored adversaries from Russia, China, and North Korea, all of whom have expanded their targeting in Europe and the U.S. in recent years. Iran denies involvement in such operations at the state level, but high-confidence reporting consistently attributes these activities to Iranian state interests.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.