The Islamic Revolutionary Guard Corps (IRGC) is a major Iranian state security and military organization that also conducts cyber operations, influence campaigns, covert action, and sanctions-evasion activity. In cyber contexts, IRGC-linked operators have been publicly associated with long-running intrusion activity against U.S. and foreign organizations since at least 2015, including targets in aerospace, satellite technology, and international government-related sectors. Reported tradecraft includes reconnaissance against personnel, harvesting publicly available personal information, creation of fraudulent identities and social media personas, spearphishing, malware delivery, unauthorized network access, privilege escalation, and establishment of additional backdoors to maintain persistence. Public reporting has also linked IRGC-associated actors to use of commodity and post-exploitation tooling such as Metasploit, Mimikatz, NanoCore RAT, shellcode stagers, and custom Python backdoors. IRGC-linked activity also includes cyber-enabled targeting support and operational intelligence collection. Reported examples include compromise of maritime situational-awareness systems to help identify vessels later struck by partner forces, and alleged exploitation of SS7 telecommunications weaknesses to geolocate U.S. military personnel in the Persian Gulf. Separate reporting has tied IRGC-affiliated actors to targeting of internet-exposed industrial control components in the water and wastewater sector, consistent with prior Iranian activity against operational technology. Beyond network intrusion, the IRGC has been repeatedly linked to covert influence and disinformation operations. U.S. government actions attributed to the IRGC include operation of disguised media personas and online properties aimed at U.S. and international audiences, including efforts to influence U.S. public opinion and the 2020 U.S. presidential election. Treasury actions have also identified the IRGC-Qods Force and associated propaganda fronts, including Bayan Rasaneh Gostar Institute, the Iranian Islamic Radio and Television Union, and the International Union of Virtual Media, as components of this influence apparatus. The IRGC has additionally been tied to transnational coercion, assassination plotting, and collaboration with criminal or proxy networks. Reporting has described IRGC-linked operators using organized crime and drug-trafficking intermediaries for surveillance, intimidation, and violence in Europe, as well as plots against U.S. officials and Iranian dissidents. Financially, the IRGC has been associated with sanctions-evasion and threat-finance ecosystems spanning shadow shipping, cryptocurrency flows, and maritime extortion. U.S. sanctions actions have described an IRGC-backed scheme forcing commercial vessels to purchase maritime insurance for transit through the Strait of Hormuz, and other reporting has linked IRGC-associated financial activity to large-scale cryptocurrency transfers and cross-border sanctions-evasion networks. Known aliases include Iranian Revolutionary Guards, Islamic Revolutionary Guard Corps (IRGC), and IRGC cyber units. Subcomponents referenced in public reporting include the IRGC-Qods Force (IRGC-QF).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
90 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian military/security force activity in and around the Strait of Hormuz, including high-speed craft presence and maritime pressure associated with the broader regional conflict and sanctions environment.
The content describes the IRGC as central to Iran’s crypto-based sanctions evasion and illicit finance ecosystem, with billions of dollars in inflows to associated addresses tied to ransom payments, sanctioned oil, and procurement activity.
Conducting or supporting maritime security and coercive activity in and around the Strait of Hormuz, including elevated high-speed craft presence amid sustained kinetic pressure at the eastern approach.
Suspected Iranian-linked actors potentially tied to the IRGC are being investigated for cyberattacks disrupting U.S. water and wastewater operational technology by targeting internet-exposed PLCs and remote management equipment. The article also notes prior 2023 activity by IRGC-affiliated actors against water facilities using internet-connected controllers with default passwords.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.