Iran — Cyber Threat Profile

Iran's cyber doctrine blends strict domestic control with asymmetric operations abroad. Critical events, including the 2010 Stuxnet attack,prompted Tehran to build significant cyber capabilities. Iran now invests heavily in offensive operations, often through the IRGC's cyber units and the passive defense organization. Experts note Iran as "one of the five most active states" in cyberspace, with operations spanning espionage to disruptive attacks. Iran primarily targets regional rivals (energy firms in the Gulf, Israeli infrastructure) via APT groups (e.g. APT33/34/35) and proxies (Hacktivist cells). Domestically, Iran enforces extensive internet censorship and surveillance.

Read the full analysis on IntelFusions