The Islamic Revolutionary Guard Corps (IRGC) is an Iranian state military and security organization. Its cyber-associated personnel and affiliates have conducted espionage operations against U.S. and foreign organizations since at least 2015, particularly organizations connected to aerospace, satellite technology, and international government work. Documented operations include open-source reconnaissance of targeted personnel, fraudulent online identities and social-media impersonation, tailored spear-phishing, malware-enabled network intrusion, theft of sensitive business, intellectual-property, and vendor information, and follow-on creation of backdoors and privilege escalation. IRGC-linked activity has also supported covert influence operations that masqueraded as independent media outlets to disseminate pro-Iranian narratives and attempt to influence U.S. audiences and elections. The IRGC-Qods Force (IRGC-QF) and IRGC-linked entities have been associated with these propaganda efforts. The organization has additionally been linked to maritime coercion and sanctions-evasion activity, including an extortion scheme targeting commercial shipping transiting the Strait of Hormuz. Known aliases include Iranian Revolutionary Guards and Islamic Revolutionary Guard Corps cyber units.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
92 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted kinetic drone and missile strikes against AWS physical data-center infrastructure in Bahrain and the United Arab Emirates during the 2026 armed conflict, causing permanent customer-data loss and regional service disruption.
Iranian military/security force activity in and around the Strait of Hormuz, including high-speed craft presence and maritime pressure associated with the broader regional conflict and sanctions environment.
The content describes the IRGC as central to Iran’s crypto-based sanctions evasion and illicit finance ecosystem, with billions of dollars in inflows to associated addresses tied to ransom payments, sanctioned oil, and procurement activity.
Conducting or supporting maritime security and coercive activity in and around the Strait of Hormuz, including elevated high-speed craft presence amid sustained kinetic pressure at the eastern approach.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.