Skip to main content
Mallory
🇮🇷 🇺🇸 IR

IRGC

Also known asiranian_revolutionary_guardsirgcislamic_revolutionary_guard_corps

The Islamic Revolutionary Guard Corps (IRGC) is an Iranian state military and intelligence organization referenced in the content as a threat actor spanning physical, cyber, financial, propaganda, and maritime activity. Known aliases in the provided content include Iranian Revolutionary Guards and IRGC. The content also specifically mentions the IRGC’s Quds Force. Based on the provided material, the IRGC has been linked to recruitment and incitement of overseas threat actors for targeted attacks and assassinations against high-profile U.S. politicians and Iranian dissidents on U.S. soil. In cyber and influence operations, the content links the IRGC to phishing targeting individuals abroad involved in Iran-related activities, including WhatsApp users; exploitation of PLCs in multiple sectors including U.S. water and wastewater systems facilities; and activity targeting or abusing commercial messaging platforms. The content also describes IRGC online propaganda, recruitment, and fundraising infrastructure across social media, streaming services, blogs, and standalone websites, including multilingual content, AI-generated videos, and cryptocurrency use to sustain and amplify operations. Financially, the IRGC is described as using cryptocurrency-linked networks and counterparties associated with sanctions evasion and illicit trade. The content states that A7-linked infrastructure had exposure to the IRGC and that one A7 address received more than USD 65 million in direct transfers from an address attributed to the IRGC. The IRGC Quds Force is also referenced in connection with cryptocurrency purchases tied to Iranian oil sales and financial support pipelines involving proxies. The content repeatedly associates the IRGC with maritime coercion and kinetic operations in and around the Strait of Hormuz and Gulf waters. Reported behavior includes control of transit corridors near Larak Island, permission-based transit regimes, direct VHF warnings to merchant vessels, deployment of high-speed craft and gunboats, drone strikes, firing on commercial vessels, vessel seizure, and broader escalation from deterrence and warning to direct engagement. Multiple incidents in the content attribute attacks or threats against commercial shipping and port infrastructure to the IRGC, including strikes on vessels such as MSC ISHYKA and SANMAR HERALD, harassment of shipping, and attacks affecting regional energy and maritime infrastructure. The content also describes IRGC threats and strikes against regional technology infrastructure and companies. It states that the IRGC threatened major U.S. technology and finance companies’ Middle Eastern facilities as legitimate targets, and that IRGC-linked or IRGC-attributed strikes affected AWS sites in the Middle East. Additional reporting in the content references threats against energy, power, information, and telecommunications infrastructure. Geographically, the content places IRGC activity in Iran, the Gulf and Strait of Hormuz, the United States, Europe, and Latin America. In Latin America, the content states that the IRGC, particularly through its Quds Force, has been expanding its presence and cooperating with local criminal networks such as drug cartels to fund operations. The content also links the IRGC to aligned or proxy ecosystems including Hezbollah, Ansar Allah/Houthis, Hamas, PIJ, and HAYI in the context of online content tracing and financial facilitation.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • IR
  • US
MITRE ATT&CK

Tradecraft

28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics28 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
4 techniques
T1589×2
Gather Victim Identity Information
T1590×2
Gather Victim Network Information
T1592
Gather Victim Host Information
T1595
Active Scanning
TA0042
Resource Development
5 techniques
T1584
Compromise Infrastructure
T1585
Establish Accounts
T1586
Compromise Accounts
T1587
Develop Capabilities
T1650
Acquire Access
TA0001
Initial Access
2 techniques
T1195
Supply Chain Compromise
T1566
Phishing
TA0002
Execution
2 techniques
T1574
Hijack Execution Flow
T1648
Serverless Execution
TA0005
Stealth
4 techniques
T1036×4
Masquerading
T1070
Indicator Removal
T1070.004
File Deletion
T1564
Hide Artifacts
T1574
Hijack Execution Flow
TA0009
Collection
1 technique
T1213
Data from Information Repositories
TA0011
Command and Control
4 techniques
T1001
Data Obfuscation
T1071×3
Application Layer Protocol
T1090
Proxy
T1573
Encrypted Channel
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
3 techniques
T1485×2
Data Destruction
T1498×4
Network Denial of Service
T1565
Data Manipulation
T1565.001×3
Stored Data Manipulation
IOCS

Observables

73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping28

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables73

Domains, IPs, and hashes tied to this actor, refreshed continuously.