Iranian authorities are state actors in Iran that have repeatedly used nationwide communications disruption as a tool of domestic repression during periods of anti-government unrest. Reported activity includes shutting down internet access across the country, restricting mobile and phone communications, and selectively restoring connectivity through a whitelist model that prioritizes government-aligned services, state media, and approved institutional networks. During a major protest-related crackdown, Iranian authorities were also reported to have disrupted satellite internet access inside Iran through sophisticated jamming directed at Starlink service. This activity reflects a state-level capability focused on controlling information flows, hindering protest coordination, and limiting the transmission of images and reporting to external audiences. The available information supports characterization as a government-operated censorship and disruption apparatus rather than a conventional named intrusion set or cybercrime group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.