U.S. authorities tied Iran to a multi-stage influence operation aimed at the 2020 presidential election, including spoofed Proud Boys emails that threatened Democratic voters, theft of data from a misconfigured state voter system affecting more than 100,000 voters, and a disinformation video that falsely portrayed election infrastructure as compromised. FBI and CISA alerts said the actors used voter intimidation emails, spoofed media sites, propaganda, and infrastructure that included VPN-backed IP addresses, while warning that parts of the video appeared staged for psychological effect even though the operators were likely capable of exploiting common web vulnerabilities.
The campaign continued after Election Day with the "Enemies of the People" website, which published personal information and death threats against election officials, security leaders, governors, and voting-system personnel who rejected fraud claims. The U.S. later charged Seyyed Mohammad Hosein Musa Kazemi and Sajjad Kashian, alleged contractors for Iran-linked Emennet Pasargad, and imposed sanctions on the company, other Iranian nationals, and IRGC-linked entities; separate Justice Department actions also seized dozens of domains allegedly used by the IRGC to run covert propaganda outlets targeting U.S. audiences.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
23 events from the most recent confirmed update back to the earliest known activity.
The Lawfare article says the ODNI analytic ombudsman reported in January that internal politicization of election interference intelligence led to biased public reporting on Russian and Chinese interference efforts. The report is cited as evidence that public emphasis on Iran may have been distorted.
On November 18, 2021, a federal indictment unsealed in New York charged Seyyed Mohammad Hosein Musa Kazemi and Sajjad Kashian for the cyber-enabled disinformation and threat campaign targeting the 2020 U.S. presidential election. The same announcement said OFAC sanctioned Emennet Pasargad, the two defendants, and four other Iranian nationals.
On December 23, 2020, the FBI and CISA said they had highly credible information indicating Iranian cyber actors were almost certainly responsible for creating the 'Enemies of the People' website. They said the post-election activity showed ongoing Iranian intent to sow division and undermine confidence in the U.S. electoral process.
By December 22, 2020, the FBI had concluded Iranian advanced persistent threat actors were almost certainly responsible for the 'Enemies of the People' website and notified targeted individuals. Federal officials linked the operation to Iran's broader election interference efforts.
In mid-December 2020, Iranian cyber actors were assessed to have created the 'Enemies of the People' website, which published personal information and death threats targeting U.S. election officials and private-sector election-related individuals. The campaign also spread across multiple domains, social media accounts, and threatening emails.
On Nov. 4, 2020, the conspirators allegedly attempted to use stolen credentials to access a U.S. media company in order to spread additional false election claims. The attempt failed because the FBI had already warned the victim and the company had mitigated the intrusion.
A seizure warrant issued on November 3, 2020 led the United States to seize 27 additional domain names allegedly used by the IRGC for a covert influence campaign. DOJ said four of the domains posed as independent news outlets targeting U.S. audiences and that the action followed the earlier seizure of 92 similar domains.
On November 3, 2020, CISA published alert AA20-304A identifying an Iranian advanced persistent threat actor as obtaining voter registration data. The FBI's later advisory referenced this alert as part of the same election interference activity.
On October 29, 2020, the FBI issued FLASH alert ME-000138-TT, coordinated with DHS/CISA, providing indicators of compromise tied to an Iran-based group assessed to be conducting election influence and interference operations. The notice linked the group to voter intimidation emails, fictitious media sites, and the propaganda video.
On October 22, 2020, CISA and the FBI published joint advisory AA20-296B warning that Iranian APT actors were likely intent on influencing and interfering with U.S. elections. The advisory said they were creating fictitious and spoofed media sites to spread propaganda and misinformation about voter suppression.
On October 22, 2020, OFAC designated five Iranian entities, including the IRGC, IRGC-QF, Bayan Gostar, IRTVU, and IUVM, for attempted interference in the 2020 U.S. presidential election. Treasury said the Iranian regime used disguised media outlets, social media, and misleading narratives to target U.S. audiences.
On October 20 and 21, 2020, Iranian actors sent spoofed emails to thousands of voters in Florida, Alaska, and Arizona while posing as the Proud Boys and threatening recipients to vote for Donald Trump. The later indictment says similar threatening emails targeted tens of thousands of registered voters, especially Democrats.
The Department of Homeland Security's Homeland Threat Assessment identified Russia as the greatest purveyor of disinformation and misinformation within the United States. This contrasted with later public emphasis on Iranian election interference.
Lawfare says the FBI seized 92 domains in October 2020 that were part of an Iranian influence network using U.S.-based web hosting services. The domains were associated with covert propaganda outlets concealing ties to Iran.
Within 48 hours of the October 20-21 email operation, then-DNI John Ratcliffe publicly attributed the disinformation campaign to Iran. The FBI FLASH says its later notice followed a joint press conference by the DNI and FBI Director on election security.
The operation included a video carrying the Proud Boys logo that purported to show hacking of state voter websites and creation of fraudulent absentee ballots. U.S. officials later assessed parts of the demonstration were simulated or fabricated for psychological effect.
Lawfare says the Trump administration reimposed severe sanctions on Iran, including its financial sector, just days before the spoofed email operation. The sanctions are presented as part of the context surrounding Iran's activity.
About a week before the spoofed Proud Boys email campaign, Iranian infrastructure suffered two major cyberattacks, including one affecting port electronic infrastructure. The Lawfare analysis cites these incidents as context for possible retaliatory behavior.
According to the 2021 indictment, the conspirators conducted reconnaissance on and attempted to compromise about 11 state voter websites, including voter registration and voter information sites. This activity formed part of the broader election interference campaign.
An August 2020 ODNI press release said China, Russia, and Iran were all conducting influence efforts related to the 2020 election. It said Iran sought to undermine U.S. democratic institutions and divide the country, while Russia primarily sought to denigrate Joe Biden.
The later DOJ indictment alleges the cyber-enabled Iranian influence campaign targeting the 2020 U.S. presidential election ran from approximately August 2020 through November 2020. Its goals included intimidating voters, undermining confidence in the election, and sowing discord.
The DOJ indictment says the conspirators successfully exploited a misconfigured computer system belonging to one U.S. state and downloaded information on more than 100,000 voters. Lawfare describes the operation as the first public-record Iranian election influence case using stolen voter information.
Treasury said Bayan Rasaneh Gostar Institute had served as an IRGC-QF propaganda front since at least 2015 and was prepared as recently as summer 2020 to run influence operations targeting the U.S. population ahead of the presidential election. Planned themes included exploiting U.S. social issues such as COVID-19 and denigrating political figures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
lawfareblog.com
Open sourcejustice.gov
Open sourcetelerik.com
Open sourcefbi.gov
Open sourcedhs.gov
Open sourcefireeye.com
Open sourcesupport.f5.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.