A cyberattack against Iran's state broadcaster, Islamic Republic of Iran Broadcasting (IRIB), briefly hijacked live programming and deployed a destructive malware toolkit inside the broadcaster's environment. During the intrusion, broadcasts were interrupted to display images of Maryam and Massoud Rajavi and a message calling for the assassination of Supreme Leader Ayatollah Ali Khamenei, indicating the operation combined political messaging with sabotage of media operations.
Check Point's investigation said the attackers used multiple custom components, including backdoors, batch scripts, configuration files, and a wiper designed to corrupt files, erase the master boot record (MBR), clear Windows Event Logs, delete backups, kill processes, and change user passwords. The attackers also deleted the executable for the TFI Arista Playout Server and forced a malicious video file, TSE_90E11.mp4, to loop on air; researchers said they could not confirm attribution or the initial access vector, but assessed the operation showed detailed knowledge of IRIB's broadcast infrastructure and may have involved insider assistance or coordination between groups.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
On January 27, 2022, attackers breached Iran's state broadcaster IRIB, briefly hijacked an on-air broadcast for about 10 seconds, and displayed images of Maryam and Massoud Rajavi with a message calling for the assassination of Ayatollah Ali Khamenei. The intrusion also involved multiple custom malware components and a wiper intended to disrupt broadcasting operations and damage infected systems.
Check Point published findings on the IRIB attack, detailing the malware toolkit, including backdoors, batch scripts, and a wiper, and describing how the attackers deleted the TFI Arista Playout Server executable and looped a malicious video file. The company said it could not formally attribute the attack or determine the initial access vector, while assessing that the operation showed strong internal knowledge of IRIB's environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.