Skip to main content
Mallory
🇮🇷 IR

APT Iran

Also known asapt_iran

APT Iran is a self-styled pro-Iran hacktivist or state-aligned cyber persona active on Telegram and darknet marketplaces, associated in the reporting with disruptive operations, data-theft claims, ransomware-style extortion, and OT/ICS-themed activity. The actor is described as conducting operations against Israeli infrastructure and against Gulf states perceived as aligned with Israel or the United States, including Jordan, Saudi Arabia, Bahrain, and Kuwait. Reported targets also include Israeli academic and government systems, Jordanian critical infrastructure, U.S. defense contractor Lockheed Martin, and a U.S. water treatment control system. Across the cited reporting, APT Iran claimed a month-long intrusion into Jordanian critical infrastructure, including alleged manipulation of power plant controls to reduce electricity output and intrusion into grain storage systems with claimed manipulation of storage temperatures and wheat-weight reporting. It also published a screenshot of what appeared to be an active HMI panel for a Kupferle Water Solutions water treatment control system in Missouri, claiming the device had been accessed, rebooted, and backed up; these OT/ICS claims were noted as unverified in the reporting. The actor was also cited as engaging in data exfiltration and ransomware attacks on Israeli academic and government systems. APT Iran publicly claimed to have exfiltrated 375 TB of data from Lockheed Martin, including purported F-35 blueprints, and to be selling the data for more than $598 million or demanding a ransom exceeding $400 million to prevent sale to U.S. adversaries. Reporting noted these claims were promoted via Telegram and on the Russian-language darknet marketplace Threat Market, and at least one assessment described the Lockheed Martin claim as implausible and unverified. Sophos reporting characterized the group’s observed activity more broadly as DDoS attacks, website defacements, and unverified compromise claims involving Israeli infrastructure. The actor has also been linked to the marketing of an offensive OT framework via Tor-accessible marketplaces, promoted as a tool for industrial and military control-network exploitation, including capabilities related to protocol scanning and electric-grid manipulation. Reporting states the APT IRAN channel advertised the framework and teased a demo focused on “the insecurity of the United States of America.” Multiple sources in the content associate APT Iran with Iranian state structures. The reporting says researchers found links between the APT IRAN channel and the Islamic Revolutionary Guard Corps (IRGC), describes the actor as closely linked to CyberAv3ngers, and notes some sources claim APT Iran is effectively a rebranding or subdivision of IRGC cyber elements, including the IRGC Cyber Command (IRGC-CEC). These links are reported claims in the source material. Known aliases or related identities mentioned in the content include Brona Blanco, a Telegram identity reportedly adopted after attention around the Lockheed Martin claims, and Cyber4vengers/CyberAv3ngers as closely linked or overlapping entities.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Military

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics16 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
TA0001
Initial Access
3 techniques
T1133
External Remote Services
T1190
Exploit Public-Facing Application
T1566
Phishing
TA0002
Execution
1 technique
T1648
Serverless Execution
TA0003
Persistence
1 technique
T1133
External Remote Services
TA0007
Discovery
1 technique
T1580
Cloud Infrastructure Discovery
TA0009
Collection
1 technique
T1074
Data Staged
TA0010
Exfiltration
5 techniques
T1020
Automated Exfiltration
T1041×2
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1537×2
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
2 techniques
T1491
Defacement
T1491.001
Internal Defacement
T1498
Network Denial of Service
ACTIVITY FEED

Recent activity

13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping15

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.