Also available in Persian — نسخه فارسی EN فا
🔴 Breaking ❓ Unknown

U.S. Intelligence and Cybersecurity Agencies Warn of Ransomware Efforts by Hackers Linked to the Islamic Republic

Apr 17, 2026 April 17, 2026 7 min read 📰 VOA Persian
📋 Key Takeaway

U.S. intelligence agencies have issued a warning about hackers linked to the Islamic Republic attempting to deploy ransomware and target various sectors, including the Trump campaign. Microsoft has identified Iranian actors using malware in key industries. This situation raises concerns about foreign interference in the upcoming U.S. elections.

🔍 Quick Context Guide
💡 Bottom Line: Iranian hackers are increasingly targeting U.S. political figures and sectors.

👥 Key Players

Peach Sandstorm ACTOR
Iranian hacking group
"an Iranian actor known as 'Peach Sandstorm' has deployed malware"
Donald Trump (دونالد ترامپ) TARGET
Former President of the United States
"hackers affiliated with the Islamic Republic recently targeted the campaign of Donald Trump"
John Bolton (جان بولتون) TARGET
Former National Security Advisor
"target a former government official and trusted advisor to Trump, John Bolton"
Islamic Revolutionary Guard Corps (سپاه پاسداران انقلاب اسلامی) LINKED
Iranian military organization
"operates under the auspices of the Islamic Revolutionary Guard Corps"
FBI (اف‌بی‌آی) QUOTED
Federal Bureau of Investigation
"issued a recommendation stating that hackers likely associated with the Iranian government"
Cybersecurity and Infrastructure Security Agency (آژانس امنیت سایبری و زیرساخت) QUOTED
U.S. government agency
"issued a recommendation stating that hackers likely associated with the Iranian government"

⚡ Actions

FBI, Cybersecurity and Infrastructure Security Agency, Cyber Crime Center ANNOUNCE educational, financial, healthcare, defense organizations
"hackers likely associated with the Iranian government are collaborating with prominent ransomware groups"
Confidence: 90%
Iranian hackers TARGET Donald Trump's campaign
"hackers affiliated with the Islamic Republic recently targeted the campaign of Donald Trump"
Confidence: 90%
Peach Sandstorm DEPLOY satellite, oil and gas, communications sectors
"an Iranian actor known as 'Peach Sandstorm' has deployed malware in the satellite, oil and gas, and communications sectors"
Confidence: 90%

📰 What Happened

U.S. agencies warn of Iranian hackers collaborating on ransomware targeting various sectors.

  • FBI, Cybersecurity and Infrastructure Security Agency, Cyber Crime Center announce educational, financial, healthcare, defense organizations
  • Iranian hackers target Donald Trump's campaign
  • Peach Sandstorm deploy satellite, oil and gas, communications sectors

💡 Why It Matters

🇮🇷 For Iran: Because Iran seeks to undermine U.S. political stability.
🌍 Regional: Because it reflects Iran's aggressive cyber operations in the Middle East.
🌐 International: Because it poses a threat to U.S. cybersecurity and foreign policy.

📚 Background

Iranian hackers are increasingly targeting U.S. political figures and sectors.

📝 Key Evidence

"hackers likely associated with the Iranian government are collaborating with prominent ransomware groups"
→ This proves the Iranian government's involvement in cyber activities.
"hackers affiliated with the Islamic Republic recently targeted the campaign of Donald Trump"
→ This indicates a direct attack on a U.S. political figure.
📡 Source: INTERNATIONAL
📊 Confidence: 80%
VOA Persian is generally considered a reliable source for international news.

U.S. intelligence agencies have warned about the activities of hackers linked to the Islamic Republic aimed at facilitating ransomware deployment. On Wednesday, September 7, three U.S. agencies—the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency, and the Cyber Crime Center of the Department of Defense—issued a recommendation stating that hackers likely associated with the Iranian government are collaborating with prominent ransomware groups to gain access to educational, financial, healthcare, and defense organizations. According to this recommendation, the hackers intend to claim a portion of the extortion proceeds in exchange for assisting in the deployment of ransomware. The recent warning from intelligence and cybersecurity agencies regarding the nature of hacking operations supported by the Islamic Republic follows multiple recent reports on this issue. CNN also reported that hackers affiliated with the Islamic Republic recently targeted the campaign of Donald Trump, the former President of the United States and Republican candidate in the upcoming elections. Simultaneously, Microsoft announced that an Iranian actor known as "Peach Sandstorm" has deployed malware in the satellite, oil and gas, and communications sectors in the U.S. and the United Arab Emirates. Microsoft indicated that this Iranian group operates under the auspices of the Islamic Revolutionary Guard Corps (IRGC) and has targeted U.S. and Australian defense, space, educational, and governmental sectors. According to U.S. intelligence agencies, the group of hackers linked to the Islamic Republic has been active since 2017, targeting local organizations and institutions in the U.S. CNN's exclusive report on September 7 examined the operations of hackers linked to the Islamic Republic ahead of the U.S. presidential elections in November. CNN stated that the Iranian hackers who recently targeted Donald Trump's campaign had previously used a similar tactic two years ago to target a former government official and trusted advisor to Trump, John Bolton, a prominent critic of the Iranian government. According to CNN, after infiltrating this individual's email account, the hackers sent a seemingly harmless request to a group of U.S.-based experts critical of the Islamic Republic, asking them to review a hypothetical book by this individual about the nuclear programs of the Islamic Republic of Iran and North Korea. In this fake email, purportedly sent by this individual, he asked the targeted experts to provide feedback on the chapters of his upcoming book after reading it. He encouraged the experts to click on an attached link to access a version that did not actually exist. After clicking, malicious codes would enter the experts' accounts, allowing the hackers unlimited access to their computers and information. According to CNN, this individual soon realized what was happening and informed the FBI and his colleagues that he had been targeted by a "very sophisticated hacking operation." Investigations by CNN indicate that these hackers were linked to the IRGC. CNN's report provides new details about the years-long operations of these Iranian hackers, who have targeted former members of both the Trump and Biden administrations. According to CNN, these hackers also targeted a senior former Biden administration diplomat in the Middle East last June in a nearly identical manner through phishing emails. In April, this diplomat received a seemingly harmless email from someone who introduced himself as a researcher from a reputable think tank in Washington. In this fake email, the individual was asked to participate in a discussion on the think tank's research topic regarding "the evolving dynamics of the situation between Israel and the Palestinians" as a Middle East expert. According to CNN, it is unclear whether the hackers were successful in this operation, as the former diplomat has refrained from commenting on the matter. However, potential access to such an individual's email would provide valuable information to the hackers for targeting Democratic Party foreign policy circles in future operations. According to CNN, the Islamic Republic's relentless efforts to hack current and former American officials have recently caught the attention of U.S. intelligence agencies. Experts believe that the Iranian government is attempting to exacerbate divisions in the United States as one of the most aggressive foreign powers ahead of the U.S. presidential elections. After Trump's campaign reported that its email systems had been hacked by hackers working for the Islamic Republic of Iran, analysts and security experts warned on Sunday, August 12, that there could be broader efforts by foreign powers to disrupt the U.S. presidential elections. So far, Eric Swalwell and Adam Schiff, two Democratic members of the House of Representatives from California who have been involved in intelligence and security committees, have called for explanatory sessions and the declassification of information related to potential foreign interference in the elections. News organizations, including The Washington Post and Politico, reported that in recent weeks they received documents labeled "special and confidential" from an anonymous user named "Robert" containing information about internal investigations concerning J.D. Vance, Trump's vice-presidential candidate. Trump's campaign referenced a report published by Microsoft on Friday, August 10, which discussed evidence of attempts by Iranian hackers to breach the email account of a "high-ranking official" in U.S. election campaigns last June. The company did not provide further details, but a source familiar with Microsoft's work confirmed that the report referred to Trump's campaign. It was around the same time that J.D. Vance was introduced as Trump's vice-presidential candidate should he win the upcoming elections. However, U.S. officials have not confirmed the hacking of this campaign, and Trump's campaign has not provided evidence of Iranian involvement. The Washington Post reported that the Harris-Vance campaign also did not respond to several requests for comment. The Democratic Party and affiliated organizations have emphasized the need for advanced security protocols since 2016 and have invested significantly in strengthening and protecting systems against hacking and other cybersecurity threats. Donald Trump wrote on his social media account "Truth Social": "Microsoft just informed us that the Iranian government has hacked one of our many websites - this is never a good thing!" Microsoft and other security companies state that a group of Iranian hackers managed by the IRGC was involved in this attack. According to the email security provider "Proofpoint," the Iranian hacker group also used the same method against a spokesperson for a U.S. official in 2021, and this group has a custom malware that can be used for more sophisticated attacks. Joshua Miller, a researcher at Proofpoint, states that this Iranian group actively targets politicians and members of campaign teams, and several Iranian groups attempt to approach their targets by posing as journalists. A National Security Council spokesperson stated on Saturday that the Biden administration "strongly condemns any foreign government or entity attempting to interfere in our electoral process or undermine trust in our democratic institutions." Warnings from experts about disruptions in the U.S. elections have followed reports of the hacking of Trump's campaign, an indictment against a North Korean hacker for cyberattacks on U.S. healthcare and military facilities, the disclosure of a cyberattack on OpenAI and cover-up; a threat to U.S. national security; the U.S. is offering up to $10 million in rewards for information about three sanctioned Iranian hackers; a warning from Israel's National Cyber Directorate: beware of "update" emails from Iranian hackers; the White House: recent Iranian hacking operations in the U.S. are a fresh warning to strengthen cybersecurity; Axios: Iranian-backed hackers have increased their activities in the region; Germany warns opponents of the Islamic Republic: hackers are lurking for you.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →