The Zindashti Network is an Iranian-linked illicit finance and criminal proxy network sanctioned by the United Kingdom as part of measures targeting hostile Iranian activity. It has been identified as part of a broader ecosystem used to generate illicit revenue and to support destabilizing activity associated with the Iranian state. UK sanctions action placed the network under asset freeze and director disqualification measures. The network has been associated with hostile activity affecting the United Kingdom, Europe, and the United States through the use of criminal proxies acting on behalf of Iranian interests. Reported activity places it within the nexus of illicit finance and overseas threat operations, including efforts intended to intimidate or threaten dissidents abroad. Named individuals associated with the network include multiple members of the Zarringhalam family and other linked facilitators. Related sanctioned entities include Berelian Exchange and GCM Exchange. Available high-confidence information supports characterization of the Zindashti Network primarily as a state-linked criminal and financial facilitation network rather than a conventional intrusion set. Direct evidence for specific cyber tradecraft, malware use, or intrusion lifecycle behaviors is not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.