APT Iran is an Iranian-linked, pro-Iran hacktivist persona active in geopolitical cyber campaigns, particularly those directed at Israeli interests. It has been publicly associated with the Islamic Revolutionary Guard Corps and CyberAv3ngers; reporting has also characterized it as potentially overlapping with, or rebranding, CyberAv3ngers. The actor uses Telegram extensively to encourage retaliatory cyber activity, disseminate propaganda, and publish alleged compromise data and critical-infrastructure intrusion claims. Its public activity has included claims concerning telecommunications, water, energy, industrial-control, and defense-sector targets, although many such claims have not been independently verified. APT Iran has also been associated with promotion of an alleged offensive OT/ICS framework designed for industrial and military environments; the framework's authenticity and operational use remain unconfirmed. The actor operates within a broader ecosystem of Iran-aligned hacktivist and state-adjacent personas that coordinate messaging, target selection, and disruptive campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for telecommunications outages and a water-utility breach in Texas as part of a campaign against U.S. critical infrastructure. AT&T attributed the Dallas-area outage to attempted cable theft and found no evidence supporting the cyberattack claim; researchers assessed the claim as potentially opportunistic or a hoax.
Reportedly vows to intensify attacks against water and critical-infrastructure organizations.
Named as part of the broader coalition supporting pro-Iran cyber mobilization.
Iranian-affiliated espionage actor reportedly involved in exfiltrating and attempting to sell sensitive defense-sector data, including alleged Lockheed Martin/F-35-related information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.