The IRGC-Qods Force is the external operations arm of Iran’s Islamic Revolutionary Guard Corps and is associated with both foreign influence operations and covert action abroad. It has been publicly linked to efforts to interfere in the 2020 United States presidential election through online disinformation and malign influence activity, including the use of front organizations and media-style outlets to disseminate false narratives, misleading content, and propaganda intended to sow discord among U.S. audiences. Entities tied to the organization have been described as amplifying English-language narratives, exploiting divisive social issues, and disguising state-directed messaging as independent media content. The organization has also been attributed responsibility for orchestrating antisemitic arson attacks in Australia through proxy networks, including the use of intermediaries and criminal facilitators. Reporting specifically identifies Qods Force Department 11000 in connection with those operations. These activities reflect a blend of influence operations, covert action, and use of cutouts to obscure state involvement. Known associated entities and aliases in the supplied material include the IRGC-QF, Iranian Islamic Radio and Television Union, International Union of Virtual Media, and Bayan Rasaneh Gostar Institute, which has been described as a front supporting propaganda efforts. The actor’s observed behavior includes propaganda dissemination, spoofed or disguised media activity, reconnaissance through audience and issue targeting, persistence via proxy structures and long-running influence infrastructure, and credential-focused activity in the broader context of Iranian state operations attributed in the same reporting. The actor is best characterized as a state-linked Iranian threat entity primarily motivated by espionage and foreign interference objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
State-sponsored Iranian operations in Australia involving orchestration of antisemitic arson attacks through proxy chains including Australian criminals and Iraqi militias linked to the IRGC.
Running propaganda and influence operations targeting U.S. audiences, including amplification of false narratives and disparaging content to sow discord ahead of the 2020 U.S. election.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.