Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors IRLeaks

Also known as: DarkStorm, MRHELL112, KeyBoy, APT35, Charming Kitten, Seedworm, Mango Sandstorm, Static Kitten, Cyber Av3ngers, Storm-0784, INC Ransomware, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, Group 83

Description

IRLeaks operates with a primary motive of financial gain, combining ransomware extortion, large‑scale data theft, and resale of stolen records. The group gained notoriety by breaching the Iranian food‑delivery service SnappFood (exfiltration of ~3 TB from 20 million user profiles) and compromising 23 Iranian insurance companies to offer over 160 million personal records for sale. In a recent case, IRLeaks exploited vulnerabilities in the vendor Tosan to penetrate multiple Iranian banks, demanding a $10 million Bitcoin ransom that ultimately escalated to 35 Bitcoin. The actor excels at supply‑chain attacks and credential theft via spearphishing and vishing techniques. Malware such as StealC (for data extraction) and Ghost RAT have been observed facilitating lateral movement and exfiltration over compromised command‑and‑control channels. Additionally, the group shifts tactics across campaigns—from targeting PLC equipment in OT/ICS environments to conducting distributed denial‑of‑service attacks, demonstrating operational flexibility. Communication with victims is primarily orchestrated through encrypted messaging apps (Telegram) and secure cryptocurrency transfers, enabling swift negotiation and payment collection. Their broader strategy includes propaganda elements such as logo tampering to amplify political narratives, a hallmark of Iranian cyber operations aimed at influencing public perception while accruing illicit proceeds.

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Retail
Energy
Healthcare
Telecommunications
Critical infrastructure
Media
Manufacturing
Non profit
Aviation
Education
Hospitality
Gaming

Targeted Countries / Regions

IR
AE
IL
CN
GB
US
SA
DE
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 11 hours ago

Executive Summary

IRLeaks is an Iranian‑backed threat actor that prioritizes large‑scale financial exploitation through data breaches, ransomware extortion, and market resale of stolen records. Leveraging supply‑chain compromises, spearphishing, and zero‑day exploits, the group routinely targets high‑value sectors such as banking, insurance, energy, and critical infrastructure across multiple countries. They employ sophisticated malware (e.g., Ghost RAT, StealC) and threat‑communication channels like Telegram to demand Bitcoin ransoms, while simultaneously monetizing exfiltrated data on cybercriminal marketplaces.

Goals & Targeting

IRLeaks seeks to maximize financial returns by exfiltrating sensitive data from high‑profile sectors—particularly banking, insurance, energy, and critical infrastructure—and monetizing it through ransomware demands or direct resale. The actor’s targeting scope spans Iran, the Middle East (AE, IL, SA), Europe (GB, DE, IT), North America (US), and Asia (CN). By compromising third‑party vendors, IRLeaks establishes trusted footholds that enable broad lateral movement and access to privileged accounts across multiple institutions. Strategically, the group blends destructive attacks (e.g., ransomware deployment, wiper malware) with economic exploitation, while occasionally engaging in propagation of propaganda narratives through phishing or malicious Android replications. Their objective is to pressure victims into payment while preserving long‑term revenue streams via data market sales.

Enhanced Description

Key Capabilities

  • Compromise third‑party IT vendors for initial access
  • Use lateral movement through compromised vendor tools and legitimate credentials
  • Credential harvesting via spearphishing, vishing and password reuse exploits
  • Exploitation of known vulnerabilities and zero‑day exploits to expand foothold
  • Large‑scale distributed denial‑of‑service attacks
  • Ransomware deployment and ransomware‑as‑a‑service operations
  • Exfiltration of sensitive data over command‑and‑control channels or cloud staging
  • Target OT/ICS PLC equipment from Rockwell Automation and Allen‑Bradley
  • Deploy mobile surveillance malware via malicious Android packages
  • Impersonation of trusted entities (telecoms, airlines) for deception
  • Wiper attacks to destroy or invalidate critical data
  • Propaganda activities such as logo tampering or political messaging
  • Use of encrypted communication channels (Telegram) and secure cryptocurrency transfers for ransom negotiation

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1078
T1106
T1133
T1190
T1041
T1566.001
T1605
T1485
T1499

Software / Tooling

Ghost RAT
StealC
Agent Tesla
Mimikatz
Tarnished Scorpius (Inc. Ransomware)
Malicious Android replica of Israeli Home Front Command RedAlert APK

Campaigns & Victims

IRLeaks has consistently shifted operational focus among finance, energy, and critical infrastructure sectors since 2022, exhibiting an adaptive tempo that combines supply‑chain attacks with opportunistic ransomware demands. Major incidents include the SnappFood breach (3 TB exfiltration) and multi‑bank extortion following vendor compromise of Tosan. The group also demonstrates high activity against OT/ICS devices via targeted DDoS campaigns, as observed in attacks on Rockwell Automation PLC equipment. Victims typically comprise government agencies, large banks, insurance firms, telecom operators, and international energy corporations across Iran, Gulf states, Europe, and the United States. Notable patterns include the use of Telegram for negotiation, Bitcoin or cryptocurrencies for ransom payments, and resale of stolen data on underground marketplaces. The actor’s persistence is evident in recurring use of sophisticated malware families (Ghost RAT, StealC) and evolving tactics that accommodate new defensive measures.", "ioc_patterns":["Domain‑based phishing URLs","Bitcoin payment addresses for ransom","Telegram threat‑communication channels","Phishing email delivery with attached malicious links","Vishing phone call IDs","Malicious Android application packages","DDoS traffic targeting OT/ICS devices","Zero‑day exploit activity on known software vulnerabilities","Credential harvest logs from spearphishing campaigns","Data exfiltration over compromised C2 channels"], "recommended_actions":["Implement strict patch management and vulnerability remediation for critical third‑party vendors","Enforce network segmentation within banking infrastructure to contain lateral movement","Audit and monitor vendor security practices and supply chain controls","Establish detection of illicit cryptocurrency transactions linked to ransom demands","Monitor messaging platforms (e.g., Telegram) for threat actor activity","Patch all known and zero‑day vulnerabilities in a timely manner","Harden OT/ICS equipment and restrict network access for PLCs","Deploy email filtering and spoof detection to block spearphishing campaigns","Implement multi‑factor authentication to mitigate credential theft","Monitor network traffic for anomalous DDoS patterns and block malicious IPs","Detect and prevent data exfiltration over non‑standard C2 channels","Conduct regular social engineering awareness training for employees","Apply least privilege and network segmentation best practices","Subscribe to trusted threat intelligence feeds such as CISA advisories","Secure mobile device management to vet Android applications"], "suggested_tags": ["financial exploitation", "supply chain attack", "Iranian banking sector", "Telegram‑based threats", "ransomware demand", "cryptocurrency ransom", "vendor compromise", "DDoS Attack", "Ransomware Distribution", "Phishing Campaign", "Vishing Scams", "OT/ICS Targeting", "Iran‑Backed Actor", "Malicious APK Delivery", "Zero‑Day Exploit Exposure", "Credential Theft", "Large‑Scale Data Exfiltration", "Extortion", "Cybercriminal Marketplace"], "confidence_assessment":"The analysis is built on multiple independent reports, including official indictments and reputable security vendor insights. While the breadth of evidence supports a clear picture of IRLeaks’ capabilities and motivations, precise attribution of all incidents remains uncertain due to overlapping aliases and potential false flag operations. There are gaps concerning the full timeline of activity, specific internal organizational structure, and definitive links between alleged malware families (e.g., StealC vs. Ghost RAT) in certain campaigns. Further correlation with additional IOC feeds and forensic evidence would strengthen attribution confidence.", "sources": [ "https://www.justice.gov/archives/opa/pr/three-irgc-cyber-actors-indicted-hack-and-leak-operation-designed-influence-2024-us", "https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/", "https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/"]}

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 Filename 1

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Cyber Av3ngers
  2. www.huntress.com — Cited by web research for: Telegram
  3. www.huntress.com — Cited by web research for: RobinHood

Intel Summary

9

Techniques

52

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

Critical Infrastructure
Data Exfiltration
APT
ransomware
cybercrime
financial-sector

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.