iran-cyber-espionage

Map Iranian state-sponsored cyber espionage actors and campaigns.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill iran-cyber-espionage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iran-cyber-espionage
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/iran-cyber-espionage
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill iran-cyber-espionage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This knowledge cell consolidates Iranian state-sponsored cyber espionage operations, campaigns, and actor mappings into a single, up-to-date reference for threat intelligence teams.

Core Features & Use Cases

  • Consolidated threat intel: Summarizes IRGC/MOIS-aligned actors, campaigns, and tools for quick understanding.
  • Historical context: Tracks notable operations and campaigns (e.g., Shamoon, MuddyWater, Charming Kitten) to support attribution and risk assessment.
  • Self-updating knowledge: Maintains current insights and changelog to support ongoing threat research and reporting.

Quick Start

Ask a question like "What are Iran's main cyber espionage groups and their toolsets?" to retrieve a concise briefing.

Frequently Asked Questions about iran-cyber-espionage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are Iran's main state-sponsored cyber espionage groups and their associated toolsets?

Iranian cyber espionage groups primarily include IRGC and MOIS-aligned actors such as APT33, APT34, and Charming Kitten. They utilize specific toolsets for intelligence collection, deploying campaigns like Shamoon and MuddyWater to support state objectives.

How do I track Iranian APT campaigns for strategic cyber threat intelligence?

You can track Iranian APT campaigns by accessing consolidated threat intelligence that maps IRGC and MOIS actors to their historical operations. This approach provides structured campaign data and a living changelog to support ongoing attribution and strategic risk assessment.

What historical context is available for Iranian threat actors like Charming Kitten and MuddyWater?

Historical context for Iranian threat actors like Charming Kitten and MuddyWater includes tracking notable cyber espionage operations and campaigns to support incident analysis. This data maps actor behaviors and tools to facilitate accurate threat attribution and risk assessment.

Can I use this threat intelligence for incident response involving IRGC cyber operations?

Yes, this intelligence is designed for incident analysis involving IRGC cyber operations. It delivers structured actor-campaign mappings and up-to-date insights, enabling threat researchers to accurately attribute incidents and assess strategic risks during response efforts.

Does this resource provide updates on evolving Iranian cyber espionage tactics?

Yes, the resource maintains a self-updating knowledge base with a living changelog that captures evolving Iranian cyber espionage tactics. This ensures threat intelligence teams have current insights for continuous reporting and active threat research.

How do I map Iranian cyber espionage actors to their specific malicious campaigns?

You can map Iranian cyber espionage actors to their campaigns using structured actor-campaign mappings. This consolidates IRGC and MOIS-aligned operations, tools, and historical context into a single reference for quick threat intelligence briefings.