The Iranian Persona Layer
Ten of the thirty-eight Iran-origin rows in our actor table are typed Hacktivist, and the type column is the least informative thing about them. Cyber Av3ngers carries an activist brand and an APT type because the reporting we hold — a CISA advisory and a US Treasury sanctions notice — calls it IRGC-affiliated. Handala carries a Hacktivist type while a Justice Department seizure affidavit on file lists its leak-site domains alongside those of Homeland Justice and Karma, two brands our own Void Manticore row already carries as aliases. This page publishes that pairing: the activist-branded persona on one side, the state unit vendor reporting attaches it to on the other. /threat-actors can filter by type or by country; it cannot express a join across the two, and the join is the story.
Measured 2026-08-29, only two origins in our graph carry a double-digit bench of Hacktivist-typed rows beside their APT units — Russia at 35 APT and 12 Hacktivist, Iran at 28 and 10; no other origin holds more than two. What distinguishes the Iranian bench in our data is not its size but its documentation: for Iran, the reporting we hold names the unit behind the brand — MOIS behind Void Manticore and Agrius, the IRGC behind Cotton Sandstorm, Cyber Av3ngers and Nemesis Kitten. Every one of those attributions is inherited from the vendor doing the naming, not established by us, and the member notes say which report carries each claim.
The same trick repeats at the tooling layer. Apostle is a wiper rebuilt to present as ransomware and DCSrv encrypts machines with no ransom demand behind it — both are edges in our malware graph, not prose — and the Nemesis Kitten row's own description records BitLocker deployed as the ransomware payload of an espionage operation. A destructive state operation dressed as a criminal one is the same move as a state unit dressed as a protest movement, and the malware rows below carry it.
The incident block is off. Every canonical incident row attached to this roster belongs to a single member — Handala, at one hundred rows — and this site deleted seventy-three further Handala rows on 2026-08-05 because the importer had read its propaganda blog as a leak site: dox posts on named individuals, press releases, threats and bounty offers had all been imported as breach victims. A feed from an actor whose leak site is the operation is not activity data; the method note carries the rest.
- Curated entries: 23
- 21 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Exploit Public-Facing Application (T1190) 3/4 here · 54/211 tracked
- Disable or Modify System Firewall: Windows Host Firewall (T1686.003) 2/4 here · 6/211 tracked
- System Information Discovery (T1082) 3/4 here · 67/211 tracked
- Web Service (T1102) 2/4 here · 15/211 tracked
- Acquire Infrastructure: Virtual Private Server (T1583.003) 2/4 here · 16/211 tracked
- Social Engineering: Impersonation (T1684.001) 2/4 here · 16/211 tracked
- Brute Force (T1110) 2/4 here · 17/211 tracked
- Account Discovery: Local Account (T1087.001) 2/4 here · 19/211 tracked
- Screen Capture (T1113) 2/4 here · 19/211 tracked
- Establish Accounts: Email Accounts (T1585.002) 2/4 here · 20/211 tracked
Shared tooling
- Mimikatz 2/5 here · 73/255 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Handala Hacktivist · Iran — The most prolific persona in our graph and the reason the incident block is off: 100 canonical rows, after 73 were deleted 2026-08-05 as propaganda posts the importer had recorded as victims. A DOJ seizure affidavit we hold lists handala-hack[.]to beside justicehomeland[.]org and karmabelow80[.]org — Void Manticore's brands. Inherited, not established.
- Cyber Toufan Hacktivist · Iran — Surged after the October 2023 attacks, claiming breaches of more than 40 Israeli companies. The reporting we hold titles it a group with capabilities 'beyond typical hacktivist collectives'; the data-wiper deployments alongside the leaks are the persona giveaway.
- Moses Staff Hacktivist · Iran — Encrypts victims' networks with no ransom demand — damage presented as crime. Our coverage links it to COBALT SAPLING and a second persona, Abraham's Ax, run in parallel against Saudi targets.
- Altoufan Team Hacktivist · Iran — Bahrain- and Israel-focused brand; our Cotton Sandstorm row records the reactivation of this persona as one of that IRGC-linked unit's operations.
- N3tw0rm Hacktivist · Iran — Ransomware-branded wave against Israeli firms; our row links it to Moses Staff operations — the same hands under an earlier brand.
- Iranian Avenger Hacktivist · Iran — The newest row here, emerged 2025; our profile assesses it as a fresh persona 'potentially fronting for existing IRGC-linked infrastructure'. Included as the live example of the layer still forming.
- Void Manticore APT · Iran — The clearest pairing in our table: one MOIS-linked APT row whose aliases already are the personas — Karma for Israel, Homeland Justice for Albania. Check Point's 'Bad Karma, No Justice' and the DOJ affidavit we hold document both.
- Cotton Sandstorm APT · Iran — IRGC-linked per the FBI/Treasury advisory we hold on Emennet Pasargad; blends hack-and-leak with influence operations and reactivated the Altoufan Team persona.
- Agrius APT · Iran — MOIS-linked per public reporting on file; ran fake ransomware brands while deploying wipers — the persona trick applied to the payload as much as the actor.
- Cyber Av3ngers APT · Iran — Typed APT in our table under a hacktivist brand — the inversion that proves the rule. CISA AA23-335A calls it IRGC-affiliated over US water-utility PLC exploitation, and a Treasury notice we hold sanctions actors over critical-infrastructure attacks.
- Nemesis Kitten APT · Iran — IRGC-linked (DEV-0270); deploys BitLocker as ransomware while running espionage — criminal cover at the operation level rather than the brand level.
- APT42 APT · Iran — The persona technique at individual grain: multi-persona phishing against dissidents and NGOs, per Mandiant reporting we hold. Included to show the layer runs from fake movements down to fake people.
Malware and tooling
- Apostle 1 group — Malware — Agrius tooling: a wiper rebuilt to present as ransomware — the payload equivalent of an activist brand on a state operation.
- MultiLayer Wiper 1 group — Malware — Agrius destructive tooling from the same operations the ransomware branding covered.
- ZeroCleare 2 groups — Malware — The shared edge in this cluster: our graph links it to both OilRig and Void Manticore — an espionage unit and a persona operator holding the same wiper.
- DCSrv 1 group — Malware — Moses Staff's encryptor — encryption with no ransom demand behind it, which is the whole persona argument in one binary.
- CHIMNEYSWEEP 1 group — Malware — Void Manticore tooling from the Albania operations run under the Homeland Justice brand.
Further reading
- From Hacktivist to State Proxy: How Handala Became Iran's Most Prominent Cyber Persona Nation-State — 2026-03-03 — Our attribution profile tracing Handala from hacktivist branding to state proxy — this page's thesis in article form.
- Abraham's Ax Linked to Moses Staff: COBALT SAPLING Operates Dual Hacktivist Personas Targeting Israel and Saudi Arabia Nation-State — 2026-02-16 — One operator running two personas in parallel.
- APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents Nation-State — 2026-02-16 — The individual-grain persona tradecraft.
- IRGC-Affiliated CyberAv3ngers Target Unitronics PLCs in Water, Energy, and Healthcare Sectors Across Multiple Countries Nation-State — 2026-02-16 — The Unitronics PLC campaign that put a hacktivist brand on IRGC-attributed infrastructure attacks.
- Handala Deploys Wiper Malware Disguised as CrowdStrike Fix During Global Outage Cyber Incidents — 2026-02-16 — A destructive payload delivered under the persona's brand during the CrowdStrike outage — propaganda timing as tradecraft.
- Iran's Hackers Are Shifting From Spying to Sabotaging US Infrastructure Nation-State — 2026-06-09 — The strategic frame: Iranian operations shifting from espionage toward sabotage, where personas provide the deniability.
Our coverage
The 12 most recent of 21 briefings that mention a member of this collection.
- Iran hid a spy backdoor in fake KeePass and Telegram apps 2026-09-17
- Public exploit code can take over vBulletin forums 2026-08-26
- State hackers now log in instead of dropping malware 2026-08-20
- Hackers lock water utilities out of internet-facing PLCs 2026-07-31
- Qilin lists Stryker four months after the medtech giant ruled out ransomware 2026-07-26
- CISA flags critical bugs in Rockwell and ABB industrial gear 2026-07-15
- Attacks on industrial control systems fall to a three-year low 2026-07-07
- CISA warns of critical flaws across industrial control systems 2026-06-30
- Critical flaws let attackers hijack EV charging networks 2026-06-26
- Iran's Hackers Are Shifting From Spying to Sabotaging US Infrastructure 2026-06-09
- From Hacktivist to State Proxy: How Handala Became Iran's Most Prominent Cyber Persona 2026-03-03
- Handala Claims Saudi Aramco Breach Amid Escalating Iranian Cyber Operations 2026-03-03
How this list was chosen. Membership is hand-picked and the attribution is inherited: threat_actors.origin and country_code are free text with no confidence field, and every unit-level claim here (MOIS, IRGC) is repeated from a named vendor report we hold — CISA AA23-335A and a Treasury sanctions notice for Cyber Av3ngers, Check Point plus a DOJ domain-seizure affidavit for the Void Manticore–Handala link, the FBI/Treasury advisory on Emennet Pasargad for Cotton Sandstorm — not established by us, and the links vary in strength from a sanctions designation to a single vendor's assessment. This is not the full Iranian hacktivist bench: of the ten Hacktivist-typed IR rows, Black Reward and Edalat-e Ali are anti-regime operations pointed the other way, and Cyber Islamic Resistance and Cyber Support Front are Telegram coordination bodies with thin files; all four are deliberately absent. Russia holds a larger bench (12 Hacktivist rows beside 35 APT, measured 2026-08-29) and is not this page's subject: the grouping key is the documented persona-to-unit pairing, not the existence of personas. The incident block is switched off on purpose. The only member holding canonical incident rows is Handala — 100 rows, measured 2026-08-29 — and 73 further Handala rows were deleted on 2026-08-05 because its leak site is a propaganda outlet, not a victim registry: the deleted rows were dox posts on named individuals, press releases, threats and bounty offers that the importer had recorded as breach victims. Rendering what remains under "recent activity" would present an influence operation's claims as a victim log.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.