Holy Souls is an alias used by the Iranian cyber actor Emennet Pasargad in influence and data-leak operations. The moniker has been associated with the attempted sale of stolen personal information belonging to subscribers of the French satirical magazine Charlie Hebdo in early 2023. Emennet Pasargad is widely linked to Iranian government-aligned cyber activity and has a history of influence operations, including operations involving compromised communications services and propaganda dissemination. In this context, Holy Souls appears to function as a persona for public-facing criminal-style activity intended to amplify psychological impact, spread fear, and exploit stolen data for coercive or influence purposes rather than as a distinct standalone intrusion set. High-confidence reporting ties the alias to Iranian operations rather than ordinary financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.