Horizon3.ai
Iranian Advanced Persistent Threat Intelligence Report
Pages
26
Time to read
30 mins
Publication
Language
English
Pages
26
Time to read
30 mins
Publication
Language
English
This report is a comprehensive analysis of Iranian Advanced Persistent Threat (APT) groups that have been active from 2023 to early 2026. It utilizes open-source intelligence (OSINT) gathered from various reputable sources, including CISA advisories and Microsoft Threat Intelligence, to profile key Iranian state-sponsored threat actors. The document outlines the Tactics, Techniques, and Procedures (TTPs) employed by these groups, along with specific Common Vulnerabilities and Exposures (CVEs) that they have weaponized. The report also identifies the types of devices and infrastructure targeted by these APTs. A significant feature of this report is the cross-mapping of Iranian APT exploitation techniques with NodeZero's penetration testing capabilities, which helps users understand how these TTPs can be validated within their environments. The report highlights the increase in Iranian cyber operations and provides detailed profiles of multiple APT groups, including their affiliations, primary targets, and notable campaigns conducted during the specified period.