Also available in Persian — نسخه فارسی EN فا
🔴 Breaking ❓ Unknown

From Activists to Zarif: The Goals of Cyber Attacks

Jun 9, 2026 June 9, 2026 7 min read 📰 Radio Farda
📋 Key Takeaway

A new report from the Carnegie Endowment highlights Iran's increasing cyber capabilities, targeting both domestic activists and foreign entities. The report indicates a coordinated effort between Iranian security agencies and various hacking groups, emphasizing the risks to privacy and security in the context of ongoing protests in Iran.

🔍 Quick Context Guide
💡 Bottom Line: Iran's cyber operations are a significant threat to both domestic and international entities.

👥 Key Players

Colin Anderson QUOTED
cybersecurity researcher
"This research has been ongoing for me for a long time, since we first heard about the targeting of Iranian activists."
Karim Sadjadpour QUOTED
senior researcher at Carnegie
"The report, prepared by Colin Anderson, a cybersecurity researcher, and Karim Sadjadpour..."
Mohammad Javad Zarif (محمدجواد ظریف) TARGET
former Foreign Minister of Iran
"the targeting of members of Iran's Foreign Ministry and members of Rouhani's government in recent years."
Hassan Rouhani (حسن روحانی) TARGET
former President of Iran
"the targeting of members of Iran's Foreign Ministry and members of Rouhani's government in recent years."
Iranian government (دولت ایران) ACTOR
government
"the Iranian government conducts its aggressive operations online..."

⚡ Actions

Iranian government ATTACK journalists, political critics, religious minorities, foreign governments
"These actions target a range of entities from opponents of the Iranian government inside and outside the country."
Confidence: 90%
Iranian government CONDUCT cyber espionage, destructive attacks
"Security agencies in Iran...have increasingly become skilled in cyber espionage and destructive attacks."
Confidence: 90%
Iranian hackers TARGET journalists, political critics, ordinary individuals
"Hackers target journalists, political critics, and religious minorities."
Confidence: 80%

📰 What Happened

Iran conducts cyber attacks targeting various entities, including journalists and foreign governments.

  • Iranian government attack journalists, political critics, religious minorities, foreign governments
  • Iranian government conduct cyber espionage, destructive attacks
  • Iranian hackers target journalists, political critics, ordinary individuals

💡 Why It Matters

🇮🇷 For Iran: Because it highlights the Iranian government's capability to suppress dissent.
🌍 Regional: Because it raises tensions with regional adversaries like Saudi Arabia and Israel.
🌐 International: Because it showcases Iran's cyber capabilities against Western interests.

📚 Background

Iran's cyber operations are a significant threat to both domestic and international entities.

📝 Key Evidence

"The Iranian government conducts its aggressive operations online under the guise of misleading public accounts."
→ This proves the Iranian government's strategy to obscure its cyber activities.
📡 Source: INDEPENDENT
📊 Confidence: 80%
Radio Farda is known for reporting on Iranian issues with a critical perspective.

It has been 25 years since Iran connected to the internet, and around 17 years since the internet became widely used by many Iranians. Within a year or two, the Iranian hacking community began to form, and the first arrests of Iranian bloggers also started. This marks the beginning of a detailed report from the Carnegie Endowment for International Peace in the United States that addresses Iran's cyber activities. The report, prepared by Colin Anderson, a cybersecurity researcher, and Karim Sadjadpour, a senior researcher at Carnegie, states that security agencies in Iran, like other security apparatuses around the world, have increasingly become skilled in cyber espionage and destructive attacks. These actions target a range of entities from opponents of the Iranian government inside and outside the country, civil institutions in Iran, to governmental, defense, commercial, and diplomatic organizations in the U.S., Israel, Germany, and Saudi Arabia. This recently published report, focusing on the destructive actions of the Iranian government in cyberspace, mentions that the Iranian government conducts its aggressive operations online under the guise of misleading public accounts to showcase its capabilities while shirking responsibility for such actions. Regarding this new report, Radio Farda interviewed Colin Anderson. Mr. Anderson, what time frame does your report consider for cyber activities originating from inside Iran? This research has been ongoing for me for a long time, since we first heard about the targeting of Iranian activists. However, access to raw information about how these attacks are carried out and who is behind them has been very difficult. The 2013 elections were when we gained information about phishing attacks. I have been eager to obtain information since 2009. It was just before the 2013 elections that I suddenly encountered a wave of information, whereas until then, I had not obtained any. Can you explain your research methodology a bit? Because for someone who does not have enough information in this area, your work might seem like a group hacked, and you hacked them back to obtain information. No. There is now a very specialized field in cybersecurity and research in this area, and there are techniques available to conduct research. These techniques provide the opportunity to access a wealth of information and understand who is attacking and who is the target of the attack. Let me give an example to clarify. When someone is infected with malware, that malware must return information to the attackers, usually by connecting to a web domain. For example, named maliciousmalware.com, what a researcher in this field does is usually register this domain as an expired domain or asks a service provider to redirect access to this domain to the researcher. This process is called sinkholing. When this is done, it creates a context to understand what the attacker was doing and what they were after. In many cases in this area, we have used this method, but there are many ways similar to this, but it is certainly not hacking, and as a common method, it has specific ethical considerations and is much more ethical and legal than hacking. Let's talk a bit about the targets of these attacks. Among the staff at Radio Farda, there have also been journalists targeted by these attacks. How do you categorize the victims? There are multiple groups, and for Iranians and their understanding of the political situation in their country, these groups are predictable. These groups are predictable given the history of repression by the Iranian government. Hackers target journalists, political critics, and religious minorities. Regional adversaries, such as Saudi Arabia, Israel, and also the United States and some European countries are also among the targets. Another group that is not surprising but important to discuss is that alongside the previous groups, the Iranian government itself has been a target of these attacks. In this report, we discussed the targeting of members of Iran's Foreign Ministry and members of Rouhani's government in recent years. Moreover, it was not only political critics and opponents who were targeted, but ordinary individuals who promote a way of life have also been victims of cyber attacks. Alongside these, groups that have engaged in violence against Iran and its government have also been targeted. These are groups that are targeted by many governments. You have mentioned multiple targets, from journalists and opponents of the government to members of Hassan Rouhani's government. In your report, you even referred to Foreign Minister Mohammad Javad Zarif. In recent months, the U.S. government has taken actions regarding the naming of some Iranian hackers. With such a wide range of targets, and if government officials are also targets, what is your conclusion regarding the perpetrator or perpetrators of these cyber attacks? I think one of the most important things this research does is that we are among the first researchers to independently and demonstrably show the relationship between these attacks and the Iranian government. What we did was fundamentally show that given the number of these attacks originating from within Iran, there is a type of coordination with Iranian security agencies. While there are multiple groups with various affiliations, some are linked to the Islamic Revolutionary Guard Corps and others to the Ministry of Intelligence, these actions are repeated. A very clear example in this regard is the case of those who were arrested by the IRGC in at least the last two years, and only a few hours later, before anyone even knew about their arrest, access to their accounts was performed, and malware and phishing attacks were sent from their addresses to others. These were individuals whose arrests were not known to anyone, and suddenly their accounts were used to carry out attacks. This is a very direct relationship that we have managed to outline based on several significant cases. For instance, this happened in the case of Siamak Namazi and his father Baqer Namazi, Iranian-American prisoners, as well as Nizar Zakka, a Lebanese prisoner in Iran. There have been other cases that I cannot mention for privacy reasons. Mr. Anderson, my last question is that your new report has been published at a time when Iran is witnessing protests and severe restrictions on internet access. What do you think is the importance of this report in these days? That's a good question. I think what we have shown is that beneath the surface of this censorship that people visibly see, for example, in terms of access to Telegram, there is a dangerous and harmful layer as significant as that censorship, which is targeted attacks against the privacy and security of activists' communications. We want to show that since the Green Movement in 2009, as much as the government has been trying to invest in censorship and limiting access, it has equally worked on monitoring individuals' actions. I think what we have done internationally is that although governments focus on cyber attacks against infrastructures or, for example, banks, we have shown that the same group of hackers who attacked U.S. infrastructures are also attacking political opponents of the Iranian government. The same individuals who carried out DDoS attacks against banks have also attacked opposition websites. The security of Iranians is as important as the security of U.S. infrastructures. This was actually two responses that are both important and related to each other.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →