Also known as: DarkStorm, MRHELL112, KeyBoy, APT35, Charming Kitten, Seedworm, Mango Sandstorm, Static Kitten, Cyber Av3ngers, Storm-0784, INC Ransomware, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, Group 83
IRLeaks operates with a primary motive of financial gain, combining ransomware extortion, large‑scale data theft, and resale of stolen records. The group gained notoriety by breaching the Iranian food‑delivery service SnappFood (exfiltration of ~3 TB from 20 million user profiles) and compromising 23 Iranian insurance companies to offer over 160 million personal records for sale. In a recent case, IRLeaks exploited vulnerabilities in the vendor Tosan to penetrate multiple Iranian banks, demanding a $10 million Bitcoin ransom that ultimately escalated to 35 Bitcoin. The actor excels at supply‑chain attacks and credential theft via spearphishing and vishing techniques. Malware such as StealC (for data extraction) and Ghost RAT have been observed facilitating lateral movement and exfiltration over compromised command‑and‑control channels. Additionally, the group shifts tactics across campaigns—from targeting PLC equipment in OT/ICS environments to conducting distributed denial‑of‑service attacks, demonstrating operational flexibility. Communication with victims is primarily orchestrated through encrypted messaging apps (Telegram) and secure cryptocurrency transfers, enabling swift negotiation and payment collection. Their broader strategy includes propaganda elements such as logo tampering to amplify political narratives, a hallmark of Iranian cyber operations aimed at influencing public perception while accruing illicit proceeds.
Fake Social Media Account
Targeted Sectors
Targeted Countries / Regions
Executive Summary
IRLeaks is an Iranian‑backed threat actor that prioritizes large‑scale financial exploitation through data breaches, ransomware extortion, and market resale of stolen records. Leveraging supply‑chain compromises, spearphishing, and zero‑day exploits, the group routinely targets high‑value sectors such as banking, insurance, energy, and critical infrastructure across multiple countries. They employ sophisticated malware (e.g., Ghost RAT, StealC) and threat‑communication channels like Telegram to demand Bitcoin ransoms, while simultaneously monetizing exfiltrated data on cybercriminal marketplaces.
Goals & Targeting
IRLeaks seeks to maximize financial returns by exfiltrating sensitive data from high‑profile sectors—particularly banking, insurance, energy, and critical infrastructure—and monetizing it through ransomware demands or direct resale. The actor’s targeting scope spans Iran, the Middle East (AE, IL, SA), Europe (GB, DE, IT), North America (US), and Asia (CN). By compromising third‑party vendors, IRLeaks establishes trusted footholds that enable broad lateral movement and access to privileged accounts across multiple institutions. Strategically, the group blends destructive attacks (e.g., ransomware deployment, wiper malware) with economic exploitation, while occasionally engaging in propagation of propaganda narratives through phishing or malicious Android replications. Their objective is to pressure victims into payment while preserving long‑term revenue streams via data market sales.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
IRLeaks has consistently shifted operational focus among finance, energy, and critical infrastructure sectors since 2022, exhibiting an adaptive tempo that combines supply‑chain attacks with opportunistic ransomware demands. Major incidents include the SnappFood breach (3 TB exfiltration) and multi‑bank extortion following vendor compromise of Tosan. The group also demonstrates high activity against OT/ICS devices via targeted DDoS campaigns, as observed in attacks on Rockwell Automation PLC equipment. Victims typically comprise government agencies, large banks, insurance firms, telecom operators, and international energy corporations across Iran, Gulf states, Europe, and the United States. Notable patterns include the use of Telegram for negotiation, Bitcoin or cryptocurrencies for ransom payments, and resale of stolen data on underground marketplaces. The actor’s persistence is evident in recurring use of sophisticated malware families (Ghost RAT, StealC) and evolving tactics that accommodate new defensive measures.", "ioc_patterns":["Domain‑based phishing URLs","Bitcoin payment addresses for ransom","Telegram threat‑communication channels","Phishing email delivery with attached malicious links","Vishing phone call IDs","Malicious Android application packages","DDoS traffic targeting OT/ICS devices","Zero‑day exploit activity on known software vulnerabilities","Credential harvest logs from spearphishing campaigns","Data exfiltration over compromised C2 channels"], "recommended_actions":["Implement strict patch management and vulnerability remediation for critical third‑party vendors","Enforce network segmentation within banking infrastructure to contain lateral movement","Audit and monitor vendor security practices and supply chain controls","Establish detection of illicit cryptocurrency transactions linked to ransom demands","Monitor messaging platforms (e.g., Telegram) for threat actor activity","Patch all known and zero‑day vulnerabilities in a timely manner","Harden OT/ICS equipment and restrict network access for PLCs","Deploy email filtering and spoof detection to block spearphishing campaigns","Implement multi‑factor authentication to mitigate credential theft","Monitor network traffic for anomalous DDoS patterns and block malicious IPs","Detect and prevent data exfiltration over non‑standard C2 channels","Conduct regular social engineering awareness training for employees","Apply least privilege and network segmentation best practices","Subscribe to trusted threat intelligence feeds such as CISA advisories","Secure mobile device management to vet Android applications"], "suggested_tags": ["financial exploitation", "supply chain attack", "Iranian banking sector", "Telegram‑based threats", "ransomware demand", "cryptocurrency ransom", "vendor compromise", "DDoS Attack", "Ransomware Distribution", "Phishing Campaign", "Vishing Scams", "OT/ICS Targeting", "Iran‑Backed Actor", "Malicious APK Delivery", "Zero‑Day Exploit Exposure", "Credential Theft", "Large‑Scale Data Exfiltration", "Extortion", "Cybercriminal Marketplace"], "confidence_assessment":"The analysis is built on multiple independent reports, including official indictments and reputable security vendor insights. While the breadth of evidence supports a clear picture of IRLeaks’ capabilities and motivations, precise attribution of all incidents remains uncertain due to overlapping aliases and potential false flag operations. There are gaps concerning the full timeline of activity, specific internal organizational structure, and definitive links between alleged malware families (e.g., StealC vs. Ghost RAT) in certain campaigns. Further correlation with additional IOC feeds and forensic evidence would strengthen attribution confidence.", "sources": [ "https://www.justice.gov/archives/opa/pr/three-irgc-cyber-actors-indicted-hack-and-leak-operation-designed-influence-2024-us", "https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/", "https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/"]}
No campaigns linked yet.
No observed data linked yet.
9
Techniques
52
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics