The Islamic Revolutionary Guard Corps (IRGC) is a branch of Iran’s state security apparatus that also operates as a major military, intelligence, covert action, and influence actor. In cyber and cyber-enabled operations, IRGC elements and associated cyber units have been linked to surveillance, targeting support, online propaganda, recruitment, fundraising, and attacks supporting broader Iranian military and coercive objectives. The organization is widely associated with the IRGC Quds Force and with aligned proxy and partner networks including Hezbollah, Ansar Allah (the Houthis), Hamas, and Palestinian Islamic Jihad. IRGC-linked activity spans espionage, coercion, and disruptive operations. Reported operations include compromise of maritime situational-awareness systems to support kinetic targeting, compromise of Israeli internet-connected cameras for missile targeting and battle-damage assessment, and exploitation of telecommunications signaling weaknesses to geolocate U.S. military personnel in the Gulf. The IRGC has also been tied to attempts to bypass or undermine the security of commercial messaging platforms by compromising user accounts rather than defeating encryption directly. The organization has demonstrated a blend of cyber, intelligence, military, criminal, and financial tradecraft. Reported behavior includes reconnaissance and surveillance, unauthorized access to operational technology-adjacent and internet-connected systems, collection of location and movement data, use of cryptocurrency in sanctions-evasion and financial facilitation, and online propaganda and recruitment campaigns across multiple languages and platforms. Europol-coordinated action in 2026 targeted a large IRGC-linked online ecosystem used for propaganda, recruitment, and fundraising. Separate reporting has linked IRGC-associated financial activity to cryptocurrency transfer networks used alongside other sanctioned actors. Beyond cyber operations, the IRGC has been repeatedly associated with coercive maritime activity in and around the Strait of Hormuz, including vessel intimidation, corridor control, attacks on commercial shipping, and extortionate transit-related schemes. It has also been linked to overseas assassination plotting, surveillance, intimidation, and use of criminal intermediaries in Europe and the United States, as well as expansion of influence and facilitation networks in Latin America. The dominant motivation is strategic state-directed espionage and coercive power projection in support of Iranian national and regime interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Running or backing a maritime extortion scheme in the Strait of Hormuz and exerting coercive pressure on commercial shipping through swarming high-speed craft presence and sanctions-evasion shadow fleet activity.
Backs an extortion scheme using maritime insurance and shipping control mechanisms to generate revenue, including through digital-asset payments, and benefits from Iran’s shadow-fleet oil transport network.
Controlling and enforcing maritime movement in and around the Strait of Hormuz through high-speed craft presence and corridor control, effectively closing the strait to normal commercial tanker traffic.
The content presents the IRGC as proclaiming potential targets tied to European energy infrastructure and references prior Iran-linked targeting activity in the Gulf.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.