The Islamic Revolutionary Guard Corps (IRGC) is a core Iranian state security and military institution that also operates extensive cyber, intelligence, covert action, maritime, and financial networks. In cyber and hybrid operations, IRGC-linked or IRGC-controlled units have been associated with targeting critical infrastructure, telecommunications, online platforms, and military or commercial systems in support of Iranian state objectives. Reported activity includes compromise of maritime situational-awareness systems to support kinetic targeting, exploitation of telecommunications signaling weaknesses for geolocation and targeting, online propaganda and recruitment infrastructure, and cryptocurrency-enabled sanctions evasion and threat-finance activity. IRGC-linked actors have also been tied to prior targeting of water and wastewater facilities through exposed industrial controllers. The organization is closely associated with coercive maritime operations in and around the Strait of Hormuz, including vessel harassment, corridor enforcement, seizure pressure, and an extortion scheme that forced commercial shipping to purchase IRGC-backed maritime insurance. It has also been linked to shadow-fleet support and sanctions-evasion logistics for Iranian oil exports, including the use of deceptive shipping practices and digital assets. Financially, the IRGC has been connected to large cryptocurrency flows and to networks used by other sanctioned actors. Beyond cyber operations, the IRGC—particularly through the Quds Force—has been linked to overseas surveillance, intimidation, assassination plotting, and cooperation with criminal or proxy networks. Reported areas of activity include operations against U.S. officials and Iranian dissidents, support relationships with aligned militant groups, and expansion of influence and facilitation networks in Latin America. Known aliases include Iranian Revolutionary Guards, Islamic Revolutionary Guard Corps (IRGC), and references to IRGC cyber units. The dominant motivation is espionage and state power projection in support of the Iranian government.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
82 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content describes the IRGC as central to Iran’s crypto-based sanctions evasion and illicit finance ecosystem, with billions of dollars in inflows to associated addresses tied to ransom payments, sanctioned oil, and procurement activity.
Conducting or supporting maritime security and coercive activity in and around the Strait of Hormuz, including elevated high-speed craft presence amid sustained kinetic pressure at the eastern approach.
Suspected Iranian-linked actors potentially tied to the IRGC are being investigated for cyberattacks disrupting U.S. water and wastewater operational technology by targeting internet-exposed PLCs and remote management equipment. The article also notes prior 2023 activity by IRGC-affiliated actors against water facilities using internet-connected controllers with default passwords.
Running or backing a maritime extortion scheme in the Strait of Hormuz and exerting coercive pressure on commercial shipping through swarming high-speed craft presence and sanctions-evasion shadow fleet activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.