Actor
State agencyConfirmed
Islamic Revolutionary Guard Corps
IRGC
An Iranian state organisation. Google associates the threat actor it tracks as APT42 with the IRGC and documented its 2024 campaign-related phishing; the U.S. Justice Department separately charged three alleged IRGC employees over campaign hack-and-leak activity. U.S. Treasury also identified the Cognitive Design Production Center as an IRGC subsidiary that had planned influence operations targeting U.S. voters since at least 2023. The criminal charges remain allegations unless proved in court, while Treasury's designation is an administrative finding.
Operations
Elections
Evidence Library
IndictmentU.S. Department of JusticeSeptember 27, 2024
Three IRGC cyber actors indicted for alleged 2024 U.S. election hack-and-leak operationOriginalArchived
Platform reportGoogle Threat Analysis GroupAugust 14, 2024
Iranian-backed group steps up phishing campaigns against Israel and the U.S.OriginalArchived
Official reportU.S. Department of the Treasury, Office of Foreign Assets ControlDecember 31, 2024
Treasury sanctions Russian and Iranian entities over attempted interference in the U.S. 2024 electionOriginalArchived
IndictmentU.S. Department of JusticeSeptember 27, 2024
Three IRGC cyber actors indicted for alleged 2024 U.S. election hack-and-leak operationOriginalArchived
Platform reportGoogle Threat Analysis GroupAugust 14, 2024
Iranian-backed group steps up phishing campaigns against Israel and the U.S.OriginalArchived
Official reportU.S. Department of the Treasury, Office of Foreign Assets ControlDecember 31, 2024
Treasury sanctions Russian and Iranian entities over attempted interference in the U.S. 2024 electionOriginalArchived