SEPAHCYBERY is an Iranian psychological warfare and influence-oriented cyber group linked to the Islamic Revolutionary Guard Corps (IRGC). It has been identified as part of the broader Iranian cyber ecosystem active during the June 2025 Iran–Israel conflict, where state-backed actors, proxies, and aligned hacktivist elements used online operations to intimidate civilians, undermine Israeli morale, and amplify Iran’s wartime narrative. SEPAHCYBERY is notable for high-volume propaganda and messaging activity on Telegram, a platform used by Iranian-aligned cyber actors for recruitment, coordination, and information operations. The group is associated with psychological operations rather than clearly demonstrated bespoke intrusion tradecraft. Its observed role fits within Iranian proxy and influence operations that blend cyber-themed claims, propaganda, and intimidation. In this ecosystem, Iranian-aligned actors publicly promoted alleged hacks, data leaks, and disruptive actions, while some claims across the broader network were assessed as exaggerated, recycled, or intended primarily to manufacture panic. SEPAHCYBERY’s activity is therefore best characterized as IRGC-linked cyber-enabled influence and propaganda support rather than a purely technical intrusion set. SEPAHCYBERY has been linked to wartime online threat messaging and narrative amplification targeting Israel during the 2025 conflict period. Its behavior aligns with influence operations, spoofed or exaggerated claims of cyber impact, and coordination through social platforms used by Iranian proxy and hacktivist communities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.