APT Iran is a pro-Iran hacktivist and likely state-aligned cyber persona active in campaigns tied to Iranian geopolitical objectives, especially against Israel and, more recently, Gulf states and Western defense-related targets. The actor is commonly referred to as APT Iran or APTIran and has also appeared in reporting as part of a broader ecosystem of Iran-aligned online personas operating through coalition structures such as the Electronic Operations Room of Islamic Resistance Axis. Multiple assessments describe links or overlap with CyberAv3ngers, and some reporting associates the persona with elements of the Islamic Revolutionary Guard Corps, including possible ties to IRGC cyber command structures, although the precise organizational relationship is not publicly established with high confidence. APT Iran has been observed or claimed in operations involving distributed denial-of-service attacks, website defacements, hack-and-leak activity, ransomware-style extortion, data exfiltration claims, and alleged operational technology and industrial control system targeting. Its targeting has centered on Israeli government, academic, and critical infrastructure entities, with additional claimed activity against Jordanian and Gulf-state infrastructure, including energy, water, grain storage, and other industrial environments. The actor has also been associated with high-profile claims involving major Western aerospace and defense organizations. APT Iran has used Telegram heavily for propaganda, recruitment, operational claims, leak promotion, and calls for retaliatory cyber activity. The group’s public behavior blends disruptive operations with psychological and information effects. Reporting consistently notes that many of its claims remain unverified or appear exaggerated, particularly around large-scale critical infrastructure compromise and major data theft assertions. Even so, third-party reporting has attributed APT Iran to several significant anti-Israel campaigns, and the persona is treated as part of the broader Iranian proxy and influence ecosystem rather than as a purely independent hacktivist brand. APT Iran has also been linked to the promotion or sale of offensive OT and ICS tooling advertised as capable of targeting industrial and military control networks, including electric-grid-related protocols. These claims, like many of the actor’s publicized capabilities, remain difficult to validate independently, but they align with a broader pattern of Iranian-aligned interest in cyber-physical disruption and critical infrastructure access. Overall, APT Iran is best understood as a politically motivated, pro-Iran cyber persona that combines hacktivist branding, coercive messaging, and possibly state-linked tradecraft. Its known aliases include APTIran and APT IRAN. It operates within a wider constellation of Iran-aligned groups and personas that includes CyberAv3ngers, Handala Hack, Cyber Islamic Resistance, DieNet, Keymous, and other coalition or amplification channels used to project Iranian cyber retaliation and influence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian-affiliated espionage actor reportedly involved in exfiltrating and attempting to sell sensitive defense-sector data, including alleged Lockheed Martin/F-35-related information.
Iran-aligned persona observed operating through the Electronic Operations Room of Islamic Resistance Axis.
Pro-Iranian hacktivist/cyber persona using Telegram and a Russian-language darknet marketplace to promote an alleged Lockheed Martin data breach, inflate breach significance, and reactively change identity under perceived pressure.
Named pro-Iranian activity cluster/persona involved in retaliatory cyber operations targeting Israeli and Western entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.