Storm-2035 is an Iranian covert influence operation focused on political narrative shaping rather than traditional network intrusion. The operation has been publicly linked to Iran and has used generative AI to produce long-form articles, short social media comments, and multilingual political messaging in English, Spanish, French, and Arabic. Its content has promoted pro-Iran, pro-Palestinian, and pro-Hamas narratives while opposing Israel and the United States, and it has also addressed topics such as the U.S. presidential election, immigration in the United States, Scottish independence, Venezuela, and regional political developments in Syria. The operation has distributed content through websites and coordinated social media personas, including accounts posing as both progressive and conservative voices to increase perceived authenticity and audience reach. Operators have also mixed political messaging with non-political lifestyle content and have rewritten generated drafts before publication, likely as an evasion and tradecraft measure. Reported activity includes creation of fake personas, generation of social media biographies and comments, and adaptation of messaging for different linguistic and political audiences. Storm-2035 has been described as Iranian-linked and has at times been conflated in reporting with aliases more commonly associated with Iranian cyber-espionage activity, including APT42, Imperial Kitten, and TA456; that alias mapping is not consistently corroborated for the influence operation itself and should be treated cautiously. Available reporting supports a relationship at least at the operator level between Storm-2035 and the Iranian influence network IUVM, based on shared content-generation activity. Despite broad thematic coverage and multi-platform distribution, the operation has generally been assessed as having limited authentic engagement and modest operational impact.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used AI to generate political influence content (tweets/posts) in multiple languages and operated fake social media personas to appear as local residents.
Iranian influence operation using ChatGPT to generate English/Spanish comments promoting selected political causes and praising Iran, posted by inauthentic personas claiming to be residents of multiple countries.
Iran-linked cross-platform influence operation using AI-generated articles and social media posts published via websites and X accounts; content was pro-Palestinian, pro-Hamas, pro-Iran, and anti-Israel and anti-United States.
Iranian covert influence operation that used ChatGPT to generate content focused in part on the upcoming U.S. presidential election.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.