The Iranian Persona Layer

Ten of the thirty-eight Iran-origin rows in our actor table are typed Hacktivist, and the type column is the least informative thing about them. Cyber Av3ngers carries an activist brand and an APT type because the reporting we hold — a CISA advisory and a US Treasury sanctions notice — calls it IRGC-affiliated. Handala carries a Hacktivist type while a Justice Department seizure affidavit on file lists its leak-site domains alongside those of Homeland Justice and Karma, two brands our own Void Manticore row already carries as aliases. This page publishes that pairing: the activist-branded persona on one side, the state unit vendor reporting attaches it to on the other. /threat-actors can filter by type or by country; it cannot express a join across the two, and the join is the story.

Measured 2026-08-29, only two origins in our graph carry a double-digit bench of Hacktivist-typed rows beside their APT units — Russia at 35 APT and 12 Hacktivist, Iran at 28 and 10; no other origin holds more than two. What distinguishes the Iranian bench in our data is not its size but its documentation: for Iran, the reporting we hold names the unit behind the brand — MOIS behind Void Manticore and Agrius, the IRGC behind Cotton Sandstorm, Cyber Av3ngers and Nemesis Kitten. Every one of those attributions is inherited from the vendor doing the naming, not established by us, and the member notes say which report carries each claim.

The same trick repeats at the tooling layer. Apostle is a wiper rebuilt to present as ransomware and DCSrv encrypts machines with no ransom demand behind it — both are edges in our malware graph, not prose — and the Nemesis Kitten row's own description records BitLocker deployed as the ransomware payload of an espionage operation. A destructive state operation dressed as a criminal one is the same move as a state unit dressed as a protest movement, and the malware rows below carry it.

The incident block is off. Every canonical incident row attached to this roster belongs to a single member — Handala, at one hundred rows — and this site deleted seventy-three further Handala rows on 2026-08-05 because the importer had read its propaganda blog as a leak site: dox posts on named individuals, press releases, threats and bounty offers had all been imported as breach victims. A feed from an actor whose leak site is the operation is not activity data; the method note carries the rest.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Malware and tooling

Further reading

Our coverage

The 12 most recent of 20 briefings that mention a member of this collection.

How this list was chosen. Membership is hand-picked and the attribution is inherited: threat_actors.origin and country_code are free text with no confidence field, and every unit-level claim here (MOIS, IRGC) is repeated from a named vendor report we hold — CISA AA23-335A and a Treasury sanctions notice for Cyber Av3ngers, Check Point plus a DOJ domain-seizure affidavit for the Void Manticore–Handala link, the FBI/Treasury advisory on Emennet Pasargad for Cotton Sandstorm — not established by us, and the links vary in strength from a sanctions designation to a single vendor's assessment. This is not the full Iranian hacktivist bench: of the ten Hacktivist-typed IR rows, Black Reward and Edalat-e Ali are anti-regime operations pointed the other way, and Cyber Islamic Resistance and Cyber Support Front are Telegram coordination bodies with thin files; all four are deliberately absent. Russia holds a larger bench (12 Hacktivist rows beside 35 APT, measured 2026-08-29) and is not this page's subject: the grouping key is the documented persona-to-unit pairing, not the existence of personas. The incident block is switched off on purpose. The only member holding canonical incident rows is Handala — 100 rows, measured 2026-08-29 — and 73 further Handala rows were deleted on 2026-08-05 because its leak site is a propaganda outlet, not a victim registry: the deleted rows were dox posts on named individuals, press releases, threats and bounty offers that the importer had recorded as breach victims. Rendering what remains under "recent activity" would present an influence operation's claims as a victim log.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions