A joint advisory from the FBI, U.S. Cyber Command Cyber National Mission Force, the U.S. Department of the Treasury, and the UK National Cyber Security Centre says cyber actors working on behalf of Iran’s Islamic Revolutionary Guard Corps are conducting social-engineering and phishing campaigns against personal and business accounts. The activity has targeted people connected to Iranian and Middle Eastern affairs, including current and former senior government officials, think tank personnel, journalists, activists, lobbyists, and more recently individuals associated with U.S. political campaigns. The operators reportedly impersonate trusted contacts, journalists, relatives, or email providers, build rapport over time, and then direct victims to credential-harvesting pages that also capture multi-factor authentication codes.
The advisory says successful compromises can lead to suspicious logins, unauthorized email forwarding rules, connections from unknown devices or applications, message theft and deletion, and attempts to pivot into additional accounts. Authorities urged organizations to strengthen phishing awareness, deploy anti-spoofing protections, disable external auto-forwarding where possible, monitor mailbox-rule changes, enable alerts for anomalous logins, and adopt phishing-resistant MFA, including hardware-backed authentication methods. The references provided did not supply usable details tying the second document to this activity, so the reported event is defined by the joint warning on IRGC-linked account targeting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The FBI, U.S. Cyber Command Cyber National Mission Force, U.S. Treasury, and the UK National Cyber Security Centre published a joint advisory describing the IRGC-linked activity, indicators of compromise, historical malicious domains, and mitigation recommendations. The guidance highlighted suspicious logins, malicious forwarding rules, unknown device connections, message exfiltration, and the use of phishing-resistant MFA.
Cyber actors working on behalf of Iran's Islamic Revolutionary Guard Corps targeted personal and business accounts through social engineering, phishing pages, and theft of credentials and two-factor authentication codes. Targets included people connected to Iranian and Middle Eastern affairs such as officials, journalists, activists, think tank staff, lobbyists, and later individuals associated with U.S. political campaigns.
CISA, FBI and partner agencies released a joint advisory detailing Cl0p's exploitation of the MOVEit vulnerability, associated tactics, and recommended mitigations. The advisory formalized government guidance for organizations responding to the campaign.
Progress Software disclosed the MOVEit Transfer vulnerability and issued security updates and mitigation guidance for customers. Defenders were urged to patch immediately and restrict public exposure of vulnerable MOVEit instances.
The Cl0p ransomware gang began exploiting a SQL injection vulnerability in Progress MOVEit Transfer to steal data from internet-facing servers and extort affected organizations. The campaign was characterized as data theft and extortion rather than widespread encryption of victim systems.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.