logo

Iran cyber operations exposed in reports from Google, Microsoft

ID: 1db409c5-1006-5b0b-bff4-5d37a94b8c83

STIX ID: report--1db409c5-1006-5b0b-bff4-5d37a94b8c83

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2024-08-29

Date Updated: 2026-05-01

...
...

Mandiant and Microsoft reports detail Iran-linked intelligence-gathering operations using over 40 fake recruiting websites and fake social media profiles to collect personal data on Farsi speakers, dissidents, and foreign collaborators, and a separate IRGC-linked group (Peach Sandstorm) deploying custom Tickler malware against satellite, communications, oil & gas, and government targets; the campaigns span from at least 2017 through March–July 2024 and combine social engineering with malware-driven espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.