Leaked documents reviewed by Flashpoint indicate that Iranian contractor Emen Net Pasargard (ENP) ran a state-sponsored ransomware effort dubbed Project Signal on behalf of the Islamic Revolutionary Guard Corps (IRGC). The material shows the operation progressing from reconnaissance by ENP’s Studies Center in mid-2020 to execution by its Cyber Directorate, with ransomware attacks beginning in late October 2020. The workflow included Bitcoin payment and decryption procedures, suggesting the campaign may have blended real extortion with an effort to disguise state activity as ordinary criminal ransomware; Flashpoint also noted similarities in timing and tradecraft to the Iran-linked Pay2Key campaign targeting Israeli organizations, while stopping short of confirming a direct connection.
Separate reporting from Symantec described the sustained activity of Elfin/APT33, an Iran-linked espionage group that targeted at least 50 organizations across Saudi Arabia, the United States, and other countries in sectors including chemical, engineering, finance, telecoms, healthcare, and manufacturing. The group used spear-phishing, credential theft, commodity RATs, custom malware, and public tools, and in one case attempted to exploit CVE-2018-20250 in WinRAR against a Saudi chemical-sector target. Together, the reports show Iranian operators using both long-term intrusion tradecraft for intelligence collection and ransomware-style operations that can support disruption, coercion, or plausible deniability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
The Iranian dissident group Lab Dookhtegan released leaked ENP documents between March 19 and April 1, 2021, providing material later analyzed by Flashpoint.
Flashpoint said leaked documents indicate ENP launched a ransomware operation in late October 2020 as part of Project Signal.
Leaked ENP documents showed Project Signal was scheduled to take place between October 18 and October 21, 2020, after being assigned to ENP's Cyber Directorate with ransom listed as the goal.
Flashpoint reported that Project Signal began sometime between late July 2020 and early September 2020, with ENP's Studies Center researching target websites in preparation for operations.
In February 2019, Elfin attempted to exploit CVE-2018-20250 in WinRAR against a chemical-sector target in Saudi Arabia using a likely spear-phishing lure named JobDetails.rar. Symantec said its protection blocked the attempt.
In December 2018, Elfin came under scrutiny after being linked to a new wave of Shamoon attacks affecting Saudi Arabia.
On February 21, 2018, and again from March into April 2018, Elfin used custom FTP exfiltration tools, deployed DarkComet and additional POSHC2 implants, dumped credentials, and used PowerShell Empire commands to evade logging and AMSI protections.
On February 14, 2018, Elfin installed Quasar RAT on the infected U.S. organization's computer and used 217.147.168.123 as command-and-control infrastructure.
On February 12, 2018, Elfin sent a job-vacancy-themed email to a U.S. organization that led the recipient to download a malicious file and execute PowerShell-based malware. The attackers then established persistence and deployed an updated POSHC2 stager later the same day.
Symantec reported that the Elfin espionage group, also known as APT33, first became active in late 2015 or early 2016 and went on to attack organizations across multiple sectors.
Flashpoint analyzed the leaked documents and assessed with high confidence that Emen Net Pasargard operated the state-sponsored Project Signal ransomware effort on behalf of Iran's Islamic Revolutionary Guard Corps.
Symantec stated it found no further evidence that Elfin was responsible for the Shamoon attacks, despite overlap involving one Saudi victim and Stonedrill infection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
flashpoint-intel.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.