{"id":5895,"date":"2026-04-02T11:58:02","date_gmt":"2026-04-02T11:58:02","guid":{"rendered":"https:\/\/filter.watch\/english\/?p=5895"},"modified":"2026-04-02T14:26:53","modified_gmt":"2026-04-02T14:26:53","slug":"cyber-threat-intelligence-report-july-2025-to-march-2026","status":"publish","type":"post","link":"https:\/\/filter.watch\/english\/2026\/04\/02\/cyber-threat-intelligence-report-july-2025-to-march-2026\/","title":{"rendered":"From Massacre to War;  Escalation of Cyber and Transnational Repression Amidst Digital Blackout"},"content":{"rendered":"<h4><b>Executive Summary and Trends<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The third installment of the Iran Cyber Threats report series has been published following a delay caused by the rapid developments of the <\/span><b>Dey protests (late December 2025\u2013January 2026)<\/b><span style=\"font-weight: 400;\"> and escalating military tensions. Given the sensitivity of this period and the emergence of new threat patterns, the data collection for this report was exceptionally expanded to cover an eight-month window from <\/span><b>July 2, 2025, to March 21, 2026<\/b><span style=\"font-weight: 400;\">. This report is being released while Iranian users\u2019 right to internet access has been <\/span><a href=\"https:\/\/filter.watch\/english\/2026\/03\/17\/network-monitoring-report-march-2026-will-the-december-blackout-in-iran-happen-again\/\"><span style=\"font-weight: 400;\">violated<\/span><\/a><span style=\"font-weight: 400;\"> for more than 25 consecutive days during the ongoing conflict involving Israel, the United States, and Iran.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5896\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Cyber-Threats-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">Data from July 2 to December 30, 2025, indicates a paradigm shift in digital repression, particularly regarding its transnational reach. During this period, the volume of cyber threats increased by 15% compared to the previous six months. At the same time, requests for digital security consultations surged by 67%, reflecting heightened anxiety among users\u2014including those not personally targeted\u2014both inside and outside of Iran.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A critical turning point occurred during the nationwide <\/span><a href=\"https:\/\/filter.watch\/english\/2026\/01\/28\/network-monitoring-january-2026-from-regional-disuptions-to-total-blackout-and-whitelisted-access\/\"><span style=\"font-weight: 400;\">Dey protests<\/span><\/a><span style=\"font-weight: 400;\"> (late December 2025\u2013January 2026). Despite a total 10-day internet blackout, digital repression expanded beyond Iran\u2019s borders through various threats against activists abroad. Notably, digital rights violations during this month increased by 500% compared to the same period last year, demonstrating a powerful synergy between domestic and transnational repression tools.<\/span><\/p>\n<h4><b>From Blackout to Whitelist: Iran\u2019s Evolving Internet Control Strategy<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">All of this is taking place under conditions where, from the protests in Dey (late December\u2013January) until today, the internet in Iran has been shut down for more than 39 days. Research by Filterwatch <\/span><a href=\"https:\/\/filter.watch\/english\/2026\/01\/15\/iran-enters-a-new-age-of-digital-isolation-2\/\"><span style=\"font-weight: 400;\">indicates<\/span><\/a><span style=\"font-weight: 400;\"> that, given the Iranian government\u2019s new policies, there is no clear prospect of internet connectivity being restored. The government is rapidly expanding domestic services on the National Information Network (NIN). The website <\/span><i><span style=\"font-weight: 400;\">Iran.ir<\/span><\/i><span style=\"font-weight: 400;\"> has become a central hub for this situation, with more services being introduced on it every day.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5897\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_-1024x576.png\" alt=\"\" width=\"750\" height=\"422\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_-1024x576.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_-300x169.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_-768x432.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_-1536x864.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_-1568x882.png 1568w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Iranir_.png 1920w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">The development of whitelist-based access is ongoing, and this strategic shift from traditional censorship to a whitelist model has caused significant side effects: many domestic services either do not function properly or do not work at all. The National Information Network is extremely slow, and people are increasingly being pushed toward domestic platforms.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Severe censorship is being enforced on domestic search engines and all local platforms. Searching for keywords such as \u201cwar\u201d or \u201cceasefire\u201d on <\/span><a href=\"https:\/\/gerdoo.me\/\"><span style=\"font-weight: 400;\">https:\/\/gerdoo.me\/<\/span><\/a><span style=\"font-weight: 400;\"> yields no results in images, videos, or news sections\u2014as if no war exists, not only in Iran but anywhere in the world.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5898\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo-1024x576.png\" alt=\"\" width=\"750\" height=\"422\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo-1024x576.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo-300x169.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo-768x432.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo-1536x864.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo-1568x882.png 1568w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Gerdoo.png 1920w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">In the <\/span><a href=\"https:\/\/zarebin.ir\"><span style=\"font-weight: 400;\">https:\/\/zarebin.ir<\/span><\/a><span style=\"font-weight: 400;\"> search engine, searching for the name \u201cMojtaba Khamenei\u201d returns only results that focus on his power and wealth outside Iran. Similarly, searching for the keyword \u201cwar\u201d produces content that presents a narrative of Iran\u2019s decisive victory in the conflict.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5899\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin-1024x576.png\" alt=\"\" width=\"750\" height=\"422\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin-1024x576.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin-300x169.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin-768x432.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin-1536x864.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin-1568x882.png 1568w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Zarebin.png 1920w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">Each gigabyte of VPN access that can connect users to the internet\u2014whether via whitelisted servers or Starlink\u2014is being sold for between 1 and 3 million tomans (approximately 6\u201324 USD), a cost <\/span><b>5\u201320 times higher than the global average for one gigabyte<\/b><span style=\"font-weight: 400;\">, effectively turning internet access into a luxury commodity that many people cannot afford.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">At the same time, the price of internet packages offered by telecom operators has also increased, although this traffic does not provide access to the global internet and can only be used to access services on the National Information Network.<\/span><\/p>\n<p><b>Most Significant Events:\u00a0<\/b><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Abduction Attempt:<\/b><span style=\"font-weight: 400;\"> A plot to deceive a London-based journalist and lure him to Iraq for the purpose of kidnapping.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Infiltration Attempts:<\/b><span style=\"font-weight: 400;\"> Targeting a London-based television network supportive of Reza Pahlavi.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Account Theft:<\/b><span style=\"font-weight: 400;\"> Targeted attempts to compromise the online accounts of Iranian-American and Iranian-British journalists in New York and London.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Website Disruption:<\/b><span style=\"font-weight: 400;\"> An attempt to disable the website of a Paris-based human rights organization affiliated with a prominent Iranian activist.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Impersonation:<\/b><span style=\"font-weight: 400;\"> Widespread impersonation of high-profile human rights advocates.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Malicious Code Delivery:<\/b><span style=\"font-weight: 400;\"> Distribution of malicious JavaScript via live television streaming links.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>MahsaAlert Disruption:<\/b><span style=\"font-weight: 400;\"> Intentional interference with the MahsaAlert platform.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Regional Expansion:<\/b><span style=\"font-weight: 400;\"> Extension of transnational threats to Iraqi civil society groups opposing the Islamic Republic\u2019s regional policies.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Starlink Crackdown:<\/b><span style=\"font-weight: 400;\"> Numerous arrests related to Starlink usage; however, these primarily resulted from lapses in basic communication security rather than advanced technical tracking.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Android Malware:<\/b><span style=\"font-weight: 400;\"> Discovery of a large-scale cyberattack campaign utilizing sophisticated Android malware.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">During this period, we witnessed the emergence and intensification of complex, multi-layered transnational threats. These began with Distributed Denial of Service (DDoS) attacks against the websites of prominent Iranian human rights activists\u2014using infrastructure linked to the Iranian government\u2014and extended to the targeted distribution of malware via platforms like Telegram.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Attackers also utilized phishing links to gain unauthorized access to the accounts of high-profile Iranian-American journalists, highlighting a clear focus on targets outside Iran\u2019s geographic borders. Furthermore, the use of Artificial Intelligence (AI) tools to generate and disseminate disinformation, along with the doxxing of activists and Iranians living abroad, has added new and dangerous dimensions to these threats.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These actions, paired with public threats from Iranian officials on state-run radio and television, signify the emergence of a systematic pattern of \u201ctransnational repression\u201d. This phenomenon combines cyber, intelligence, and media tools to reach a level of complexity and scale that distinguishes it from previous years.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Dominant Attack Patterns:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Impersonation:<\/b><span style=\"font-weight: 400;\"> Posing as trusted platforms such as Meta, Facebook, WhatsApp, Gmail, and Telegram.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Infrastructure Abuse:<\/b><span style=\"font-weight: 400;\"> Exploiting legitimate or semi-legitimate infrastructure to increase the perceived credibility of the attack.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Infrastructure Masking:<\/b><span style=\"font-weight: 400;\"> Using newly registered domains, cloud email services, shortened links, and cover domains to hide malicious intent.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Targeting:<\/b><span style=\"font-weight: 400;\"> Concentrating efforts on activists, journalists, advocates, and individuals with public roles or sensitive professional connections.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>State-Linked Evidence:<\/b><span style=\"font-weight: 400;\"> Technical and content-based indicators frequently suggest these attacks are linked to actors aligned with the Iranian government or utilize domestic Iranian infrastructure.<\/span><\/li>\n<\/ul>\n<h4><b>Transnational Repression: Statistics and Trends<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The Islamic Republic has significantly expanded its digital repression beyond Iran's borders. Nearly <\/span><b>30%<\/b><span style=\"font-weight: 400;\"> of all cases recorded between July 2 and December 30, 2025, involved diaspora civil activists and targets located outside of Iran.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5900\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeting-Patterns-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h4><b>Geographic Distribution and Growth<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The report identifies a global reach for these threats, with the primary target countries being the United Kingdom, United States, Sweden, Turkey, Germany, and France.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>United Kingdom<\/b><span style=\"font-weight: 400;\">: Remains the top target due to the concentration of Persian-language media outlets.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Turkey:<\/b><span style=\"font-weight: 400;\"> Saw a 3.3% increase in the share of attacks, likely linked to the rising rate of Iranian migration and increased diaspora activity there.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Germany:<\/b><span style=\"font-weight: 400;\"> Recorded a significant rise in threats. Referrals from Germany increased by 15% starting in late December 2025 (Dey protests). This figure surged further to 26% during the Esfand war period (February\u2013March 2026). This targeting is attributed to the high activity of opposition groups, including republicans and monarchists, residing there.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>United States:<\/b><span style=\"font-weight: 400;\"> Saw a slight decrease of 2% in its share of total attacks compared to the first half of the year.<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5901\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-World-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h4><b>Expanding the Circle of Repression<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Transnational threats are no longer limited to the Iranian diaspora. The reporting period revealed attacks targeting:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Iraqi Civil Society<\/b><span style=\"font-weight: 400;\">: 2% of cases involved Iraqi activists opposed to the Islamic Republic's regional policies.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Afghan Journalists:<\/b><span style=\"font-weight: 400;\"> 1.6% of cases targeted Afghan journalists opposed to both the Taliban and the Islamic Republic.<\/span><\/li>\n<\/ul>\n<h4><b>Targeted Organizations and Emerging Trends<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The data shows a strategic shift in who is being targeted organizationally:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Ethnic Minority Rights Defenders:<\/b><span style=\"font-weight: 400;\"> Saw a heavy focus, with attacks increasing from 24% to 32%.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Media and News Outlets:<\/b><span style=\"font-weight: 400;\"> Experienced a 4x growth in attacks, rising from 3% to 12%.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Podcasting Groups:<\/b><span style=\"font-weight: 400;\"> Identified as a new target category, accounting for 9% of organizational attacks.<\/span><\/li>\n<\/ul>\n<h4><b>Special Case: Abduction Deception<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">A particularly alarming case involved an impersonation attempt designed to deceive a journalist and lure them to Iraq to facilitate a kidnapping or other transnational repression objectives.<\/span><\/p>\n<h4><b>Domestic Threats: Statistics and Trends<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">From July 2 to December 30, 2025, threats originating within Iran accounted for 71.6% of all recorded cases. This represents an 8% decrease compared to the previous period, with the shifting share of attacks moving toward targets in the United Kingdom and Turkey.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5902\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Map-Iran-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h4><b>Provincial Distribution of Threats<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">While cyber threats were documented across the country, they remained concentrated in major political and economic centers:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Tehran Province<\/b><span style=\"font-weight: 400;\">: Remains the primary target, accounting for 47% of all domestic reports, despite a 12% decrease compared to the first half of the year.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Secondary Hubs<\/b><span style=\"font-weight: 400;\">: Following Tehran, the highest volumes of reports came from East Azerbaijan, Khuzestan, Isfahan, Kurdistan, and Sistan and Baluchestan.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Rising Growth: <\/b><span style=\"font-weight: 400;\">The provinces of Fars, Markazi, and Khuzestan each saw a 3% increase in attack frequency.<\/span><\/li>\n<\/ul>\n<h4><b>Repression During the Protest Period (Late Dec. 2025 \u2013 Feb. 2026)<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Concurrent with the nationwide Dey protests (late December 2025\u2013January 2026), Miaan\u2019s \"Emergency Help Desk\" expanded its outreach, resulting in a shift in applicant patterns.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Surge in Enforcement: <\/b><span style=\"font-weight: 400;\">Referrals related to arrests and device confiscations skyrocketed to 763 cases in just 31 days.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Geographic Breadth<\/b><span style=\"font-weight: 400;\">: Requests were registered from 27 different provinces.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Major Reporting Centers:<\/b><span style=\"font-weight: 400;\"> Significant figures were recorded in Tehran (30%+), Isfahan, Razavi Khorasan, Kohgiluyeh and Boyer-Ahmad, and Alborz. Notably, 30% of applicants withheld their provincial location to ensure their personal security.<\/span><\/li>\n<\/ul>\n<h4><b>Repression During the \"Esfand War\" (Feb. \u2013 March 2026)<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Following military escalations involving the U.S. and Israel, Tehran Province again saw a spike in activity.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Capital Surge:<\/b><span style=\"font-weight: 400;\"> Cases from Tehran rose by 2%, eventually constituting nearly 40% of all referred domestic cases.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Other Affected Regions:<\/b><span style=\"font-weight: 400;\"> High report volumes followed in Markazi, Isfahan, Mazandaran, Fars, Khuzestan, and Yazd.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Security Anonymity:<\/b><span style=\"font-weight: 400;\"> More than 32% of applicants chose not to disclose their province due to heightened security concerns during the conflict.<\/span><\/li>\n<\/ul>\n<h4><b>Digital Security Consultations and Public Anxiety<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The reporting period saw a 67% jump in consultation requests, driven largely by state-sponsored disruptions and climate of fear.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Platform Specific Issues: <\/b><span style=\"font-weight: 400;\">The primary drivers were account access and security failures, particularly on Instagram and WhatsApp.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Fear of Hacking:<\/b><span style=\"font-weight: 400;\"> Many users reported \"suspicious activity\" or account suspensions, leading to widespread fear that they were being actively targeted by security agencies.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>OTP Blocking:<\/b><span style=\"font-weight: 400;\"> The Ministry of Communications intentionally blocked one-time-password (OTP) verification codes for the installation of Signal, Telegram, and Clubhouse, creating systemic obstacles for secure communication.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Device Checkups:<\/b><span style=\"font-weight: 400;\"> Following high-profile reports of hackers targeting journalists (such as those at Iran International), the Help Desk recorded a wave of requests for professional \"device security checkups\".<\/span><\/li>\n<\/ul>\n<h4><b>The Starlink Crackdown<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The use of Starlink satellite internet was explicitly <\/span><a href=\"https:\/\/filter.watch\/english\/2026\/01\/13\/network-monitoring-january-2025-internet-repression-in-times-of-protest\/\"><span style=\"font-weight: 400;\">criminalized<\/span><\/a><span style=\"font-weight: 400;\"> during the Twelve-Day War between Iran and Israel in June 2025. This provided a legal pretext for intensified judicial and security actions against satellite internet users during the total internet blackouts of both the Dey protests and the Esfand war.<\/span><\/p>\n<h4><b>Target Profiles: Individuals and Organizations<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">From July 2025 to March 2026, targeting patterns showed a clear focus on those with high social and professional capital:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Individual Concerns: 35% of all requests related to general account security, followed by political activists at 11%.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Organizational Targets: Ethnic minority rights organizations (32%) and human rights organizations (21%) remained at the top of the target list.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Media Sector Growth: The share of attacks against media organizations rose sharply from 3% to 12%.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Emerging Target: Podcast production groups were identified as a new target category, accounting for 9% of organizational attacks.<\/span><\/li>\n<\/ul>\n<h3><b>Attack Categorization<\/b><\/h3>\n<h4><b>Phishing and Social Engineering<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Phishing remained the most prevalent threat, accounting for approximately <\/span><b>39%<\/b><span style=\"font-weight: 400;\"> of all recorded cases between July 2 and December 30, 2025. The Help Desk recorded <\/span><b>54 unique cases<\/b><span style=\"font-weight: 400;\">, representing a <\/span><b>45% growth<\/b><span style=\"font-weight: 400;\"> in phishing activity compared to the first half of the year.<\/span><\/p>\n<h4><b>Dominant Techniques and Success Rates<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The primary vector for these attacks was the distribution of malicious links via Instagram direct messages, often using lures such as \"art festival surveys\" or \"Meta copyright infringement notices.\" These campaigns achieved a 38% success rate, meaning nearly four out of every ten targets clicked the malicious link.<\/span><\/p>\n<p><strong>Miaan identified four key evolutionary patterns in these attacks:<\/strong><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Platform Impersonation:<\/b><span style=\"font-weight: 400;\"> Attackers posed as support or legal teams from trusted brands like Meta, Facebook, WhatsApp, Gmail, and Telegram. Common themes included urgent warnings of account suspension, copyright claims, or fake job offers.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Telegram-Specific Campaigns:<\/b><span style=\"font-weight: 400;\"> Sophisticated attempts were observed on Telegram, including the use of fake \"support\" bots (e.g., @AuthenticatorBot) and international phone calls to pressure victims into revealing credentials. In some instances, these led to full account takeovers and ownership transfers.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Multi-Stage \"Long Con\" Phishing:<\/b><span style=\"font-weight: 400;\"> Some attackers avoided malicious links in the initial phase, instead focusing on building trust through believable pretexts such as university interviews, business collaborations, or invitations to human rights meetings. Once rapport was established, the attacker introduced the malicious link or request for sensitive data.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Infrastructure Abuse: <\/b><span style=\"font-weight: 400;\">Attackers bypassed security filters by exploiting legitimate digital trust chains, including the use of Amazon SES, link-shortening services (t.ly, shorten.ee), and high-reputation domains that successfully passed SPF, DKIM, and DMARC checks.<\/span><\/li>\n<\/ol>\n<h3><b>Malware<\/b><\/h3>\n<h4><b>Android Malware<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">A report concerning a file named PDF.apk, which was suspiciously distributed via Telegram, was initially identified as an isolated sample. This file, designed to look like a standard PDF document, served as the starting point for the discovery of an extensive cyberattack campaign. Further analysis confirms this sample is part of a broader malware cluster rather than a stand-alone case. Evidence suggests additional undiscovered samples likely exist beyond those identified.<\/span><\/p>\n<p><b>The identified samples are:<\/b><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PDF.apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vision-3187.apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PDF-977.apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PDF-572.apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unknown-8663.apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PhotoAi1.0 (1).apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artificial Intelligence.apk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PhotoAi-741.apk<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">All samples share the package name com.chvi.pool and belong to a single malware family and operational campaign, most likely managed by a specific individual or group.<\/span><\/p>\n<h4><b>Malware Cluster and Sample Correlation<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Structural and behavioral analysis reveals that these samples are part of an integrated Android malware infrastructure managed by a common actor. Shared characteristics include the package name, similar runtime behavior, common server communication patterns, and shared infrastructure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This infrastructure attempts to hide the real command-and-control (C2) infrastructure by using Domain Rotation techniques and Cloudflare as a reverse proxy. However, further analysis showed that in one of the samples, the real backend IP was exposed, making it possible to identify the main infrastructure.<\/span><\/p>\n<h4><b>Technical and Behavioral Features<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Static and dynamic analysis of the samples shows that these malware samples have a set of advanced capabilities for concealment, persistence, and information gathering:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Concealment:<\/b><span style=\"font-weight: 400;\"> Obfuscation, code encryption, and dynamic class loading via Reflection.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Persistence:<\/b><span style=\"font-weight: 400;\"> Use of \"Foreground Services\" and \"WakeLock\" to prevent the application from being stopped by the system.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Anti-Analysis:<\/b><span style=\"font-weight: 400;\"> Detection of debuggers and sandbox environments to bypass conventional analysis tools.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Stealth:<\/b><span style=\"font-weight: 400;\"> In the PDF.apk sample, the application icon is hidden from the user immediately after execution.<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5903\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Malware-Cluster-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">In the PDF.apk sample, application icon-hiding behavior was also observed, such that the application becomes invisible to the user after execution. This behavior may also be present in the other samples, even if it was not activated in the Sandbox environment.<\/span><\/p>\n<h4><b>Surveillance Capabilities and Operational Risk<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">These samples are classified as hidden Android loaders with surveillance functionality. They are capable of receiving secondary payloads and focus heavily on data collection, including:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Monitoring:<\/b><span style=\"font-weight: 400;\"> Accessing SMS inboxes and monitoring user communications.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Data Theft:<\/b><span style=\"font-weight: 400;\"> Collecting device environment information and enumerating all installed applications.<\/span><\/li>\n<\/ul>\n<h4><b>Command and Control (C2) Infrastructure<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The campaign utilizes a multilayered architecture to conceal its backend operations.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5904\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Stealth-Infrastructure-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h5><b>Layer One: C2 Domains<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">The following domains were observed in the samples:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">c978e75f17.tc<\/span><span style=\"font-weight: 400;\">-spin.space<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">c978e75f17.adislran.info<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">C978e75f17m.cs2-go.sbs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">c5acc344.geogo.cfd<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">In most cases, these domains resolved to Cloudflare IPs:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">188.114.96.3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">188.114.97.3<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">which indicates the use of Cloudflare as a proxy layer to hide the origin server.<\/span><\/p>\n<h5><b>Layer Two: Origin Backend Discovery<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">In the Pdf-812.apk sample and also PhotoAi-741.apk, one of the domains resolved to the following IP:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">94.182.115.210<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This IP belongs to an Iranian domestic internet provider, Shatel, and with a very high probability functions as the real origin backend of the C2.<\/span><\/p>\n<h5><b>Layer Three: Direct Analysis of the Backend Server<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">Direct examination of this IP showed:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Operating system: Ubuntu<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web server: nginx 1.24<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active services: HTTPS and unusual ports (7000\/7001)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use of TLS 1.3 and a Let\u2019s Encrypt certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Most importantly: the TLS certificate presented on this server belongs to the domain melliec.site.<\/span><\/li>\n<\/ul>\n<h4><b>Connection to melliec.site<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">TLS analysis shows that:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The backend server directly presents the certificate of the domain melliec.site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">This domain is also behind Cloudflare<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">But the origin server is still directly accessible<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This indicates a weakness in OpSec implementation, because t<\/span><span style=\"font-weight: 400;\">he backend is exposed to direct access without full isolation<\/span><\/p>\n<h4><b>Reverse Proxy Behavior<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Sending direct requests to the backend with different Host values (including melliec.site and adislran.info) resulted in a 502 Bad Gateway response. This behavior shows that:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The server acts as a reverse proxy (nginx)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">There is an internal backend (application layer)<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">At the time of testing, this backend:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Either was unavailable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Or responded only to specific requests<\/span><\/li>\n<\/ul>\n<h4><b>Infrastructure Summary<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Based on all evidence:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All samples are connected to a shared infrastructure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The attacker uses Domain Rotation and Cloudflare for concealment.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The main backend is concentrated at IP 94.182.115.210.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The domain melliec.site is connected to this backend, but its exact role (operational or auxiliary) is still not certain.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The presence of the certificate on the origin indicates an operational weakness in infrastructure concealment.<\/span><\/li>\n<\/ul>\n<h4><b>Importance and Security Implications<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">This malware cluster indicates that threats have evolved beyond simple phishing to full device compromise. If successful, an attacker can establish persistence, activate surveillance, and execute secondary payloads, making this a high-risk espionage threat for targeted users.<\/span><\/p>\n<h4><b>Browser- and Web-Based Attacks<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">We have documented the execution of malicious JavaScript via a state-run live-streaming site.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Entry Point:<\/b><span style=\"font-weight: 400;\"> Attackers utilized a live-streaming website from the Islamic Republic of Iran Broadcasting (IRIB) as the primary entry point.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>January 2026 Tactics (Dey Protests):<\/b><span style=\"font-weight: 400;\"> Following the complete shutdown of the international internet, a link to the <\/span><b>IRIB Channel Six <\/b><span style=\"font-weight: 400;\">live stream was sent en masse to diaspora journalists. Attackers exploited the fact that these journalists were seeking information during the blackout to encourage clicks.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Attack Objectives:<\/b><span style=\"font-weight: 400;\"> This browser-based campaign was designed for device fingerprinting, behavior tracking, and potential session theft to prepare for more targeted phishing.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Technical Significance:<\/b><span style=\"font-weight: 400;\"> This method is particularly dangerous because it requires no file installation; merely visiting the page is sufficient to identify and track the target.<\/span><\/li>\n<\/ul>\n<h3><b>Disruptive Attacks and Infrastructure Repression<\/b><\/h3>\n<h4><b>Application-Layer DDoS with Signs of Reconnaissance and Exploitation<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">During this period, we identified a severe attack on the website of a prominent human rights institution. This was not a simple \"flood\" attack; our analysis observed the following sophisticated techniques:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Targeting of heavy paths:<\/b><span style=\"font-weight: 400;\"> Specifically \/xmlrpc.php.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Scanning:<\/b><span style=\"font-weight: 400;\"> Active use of Nmap.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Vulnerability probing:<\/b><span style=\"font-weight: 400;\"> Abnormal requests designed to identify system weaknesses.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Injection patterns:<\/b><span style=\"font-weight: 400;\"> Presence of SQL Injection (SQLi) signatures.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>User-Agent Spoofing:<\/b><span style=\"font-weight: 400;\"> Spoofing of standard browser User-Agents.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This attack represents a combination of DDoS, vulnerability reconnaissance, and attempted intrusion. Its goal was not merely to reduce service quality, but to impose digital censorship by disrupting access to a human rights platform registered in France belonging to a prominent Iranian activist. The attack was repeated a second time, indicating a determined effort by state-linked actors to silence this entity.<\/span><\/p>\n<h4><b>Technical Analysis\u00a0<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Analysis of the recorded data shows that the system in question was subjected to a distributed denial-of-service (DDoS) attack that led to severe disruption in service performance and ultimately rendered it inaccessible to ordinary users. A prominent feature of this attack is the very high concentration of traffic on one main source; the IP address 178.16.55.182 generated about 98.9 percent of all malicious requests. This pattern indicates a focused and targeted attack, not a dispersed one based on large botnets. The use of high-capacity and anonymous VPS infrastructure in Eastern Europe or Russia also indicates that the attacker used rented and scalable resources to execute the attack.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5905\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Targeted-DDoS-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">Alongside the main source, two other IPs were also observed in the attack, and they are particularly significant. The address 93.118.101.248 is linked to the infrastructure of the <\/span><a href=\"https:\/\/www.tci.ir\"><span style=\"font-weight: 400;\">Telecommunication Company<\/span><\/a><span style=\"font-weight: 400;\"> of Iran (AS58224), and the address 188.136.187.113 belongs to Tose'h <\/span><a href=\"https:\/\/fanaptelecom.ir\"><span style=\"font-weight: 400;\">Fanavari Ertebabat Pasargad Arian<\/span><\/a><span style=\"font-weight: 400;\">, or Fanap (AS206065), which was <\/span><a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0220\"><span style=\"font-weight: 400;\">sanctioned<\/span><\/a><span style=\"font-weight: 400;\"> by the United States on August 7, 2025.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The involvement of these two sources, which are linked to state or semi-state infrastructure in Iran, in the attack on this website is a critical finding. It indicates the use of sensitive infrastructure alongside public resources to disrupt the activities of human rights organizations. This combination of anonymous infrastructure and infrastructure with sovereign ties may be a sign of an increased level of complexity in the design and execution of security agencies\u2019 operations in transnational repression.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">From the perspective of impact, the data indicate a complete breakdown in service performance. The average server response time reached about 1441 seconds (nearly 24 minutes), which in practice means the service was unusable for ordinary users. Under such conditions, even if the website appears superficially available, the user experience is completely disrupted and public access is effectively lost. The recording of 63 instances of 500 and 501 errors also shows that, under excessive pressure, the server suffered a severe shortage of resources and lost the ability to process requests.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Overall, this attack can be described as a targeted DDoS attack with severe operational impact that, using a combination of rented infrastructure and infrastructure linked to telecommunications entities, was able to completely disable the service. The high concentration of traffic, the controlled attack pattern, and the level of destruction caused all indicate a planned and effective operation that goes beyond ordinary and scattered DDoS attacks.<\/span><\/p>\n<h4><b>Indirect Attack and Domain Poisoning: Disruption of Access to MahsaAlert<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The public warning platform <\/span><a href=\"https:\/\/mahsaalert.com\/\"><span style=\"font-weight: 400;\">MahsaAlert<\/span><\/a><span style=\"font-weight: 400;\"> is an information and crisis-mapping system created by Iranians outside the country and publishes information related to protests, arrests, and cases of human rights violations in Iran. With the start of tensions between the United States, Israel, and the Islamic Republic of Iran, this platform issued special wartime alerts in order to prevent collateral and indirect harm from war to civilians.<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5906\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet-1024x483.png\" alt=\"\" width=\"750\" height=\"354\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet-1024x483.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet-300x141.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet-768x362.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet-1536x724.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet-1568x739.png 1568w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Mahsanet.png 1902w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p><span style=\"font-weight: 400;\">The MahsaAlert platform, without any actual intrusion into the server or being hacked, was effectively taken offline. Raznet\u2019s <\/span><a href=\"https:\/\/www.raaznet.com\/en\/reports\/mahsaalert-malware-reputation-poisoning\"><span style=\"font-weight: 400;\">investigation<\/span><\/a><span style=\"font-weight: 400;\"> shows that an individual or group created a real sample of Windows malware (RAT), embedded the domain <\/span><a href=\"http:\/\/mahsaalert.com\"><span style=\"font-weight: 400;\">mahsaalert.com<\/span><\/a><span style=\"font-weight: 400;\"> in it as the command-and-control (C2) server, and uploaded the malware sample to platforms such as VirusTotal. When security engines and sandboxes executed this malware, the program\u2019s attempt to connect to this domain was recorded, and as a result many cybersecurity companies and cyber threat databases marked the domain as malware infrastructure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This event is an example of an indirect attack: instead of infiltrating the server, the attacker manipulated automated cybersecurity systems, damaged the domain\u2019s reputation, and caused access to it to be blocked for users and networks. The aim of the report is to warn about a structural weakness in global threat intelligence systems: many systems regard domains as malicious solely on the basis of data correlation (such as malware connecting to a domain), without verifying the actual behavior of the server.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The key point of this report is that this happened without any real intrusion into the server and became possible solely through poisoning the domain\u2019s reputation.<\/span><\/p>\n<h4><b>Common Methods Used by Attackers<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Across all analyzed cases, the following methods were dominant:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Impersonation:<\/b><span style=\"font-weight: 400;\"> Attackers posed as Telegram support, Meta\/Facebook\/WhatsApp, Gmail, organizational colleagues, researchers, or legal recruiters.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Technical Credibility Abuse:<\/b><span style=\"font-weight: 400;\"> Many phishing emails successfully passed SPF, DKIM, and DMARC checks, appearing technically valid to recipients.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Newly Registered Domains:<\/b><span style=\"font-weight: 400;\"> Attackers used professionally styled domains to build trust and conduct multi-stage attacks.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Legitimate Service Concealment:<\/b><span style=\"font-weight: 400;\"> Use of link shorteners (e.g., shorten.ee, t.ly), trackers, and cloud services to hide malicious destinations.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Multi-channel Attacks:<\/b><span style=\"font-weight: 400;\"> Combining messengers, phone calls, and threat emails to increase pressure on the victim.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Anti-analysis:<\/b><span style=\"font-weight: 400;\"> Use of manifest encryption, dynamic class loading, and Reflection to bypass security researchers.<\/span><\/li>\n<\/ul>\n<h4><b>Importance and Implications of These Attacks<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">These operations have evolved beyond simple deception:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Beyond Deception:<\/b><span style=\"font-weight: 400;\"> Attacks resulted in full account takeovers, transfer of account ownership, and long-term access.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Digital Trust as a Weapon:<\/b><span style=\"font-weight: 400;\"> Attackers turned the user\u2019s trust in legitimate brands and cloud infrastructure into a vulnerability.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Repressive Function:<\/b><span style=\"font-weight: 400;\"> These attacks restrict expression, make communication networks feel unsafe, and impose heavy psychological costs, leading to self-censorship.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Device-Level Compromise:<\/b><span style=\"font-weight: 400;\"> The discovery of the PDF.apk \/ Vision-3187.apk cluster shows a shift toward persistent, surveillance-oriented access at the hardware level.<\/span><\/li>\n<\/ol>\n<h4><b>Indicators of Connection to Iran and the Use of Iranian Infrastructure<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">In all cases, it is not possible to state with certainty which individual or entity carried out the attack. However, in several cases there is significant evidence that strengthens the possibility of a connection to actors aligned with the Islamic Republic or the use of Iranian infrastructure.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct presence of Iranian infrastructure in the DDoS attack: in the case of the attack on the human rights website, part of the attacker traffic came from the following infrastructures:<\/span>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">AS58224 affiliated with Telecommunication Company of Iran<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">AS206065 affiliated with Tose'h Fanavari Ertebabat Pasargad Arian Co. PJS<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">This is one of the most important pieces of evidence in the entire collection, because it shows that, alongside foreign VPS infrastructure, domestic telecommunications infrastructure inside Iran was also observed in the attack.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attackers used impersonation of platforms, academic figures, organizational managers, and legal entities.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A significant portion of the attacks relied on legitimate or apparently valid infrastructure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In several cases, the attack progressed to actual account takeover, transfer of ownership, and post-compromise threats.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An Android malware cluster and a case of malicious JavaScript execution show that the threats are not limited to phishing.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The DDoS attack, with reconnaissance and attempted intrusion components, indicates digital repression at the infrastructure level.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In several cases, especially those related to Telegram, the DDoS attack, and Android malware, significant signs of a connection to Iran or the use of Iranian infrastructure were observed.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Overall, these data indicate the existence of a multilayered, adaptive, and in some cases successful threat environment directed against high-risk Persian-speaking users and institutions.<\/span><\/p>\n<h3><b>Content Moderation: The War of Narratives<\/b><\/h3>\n<h4><b>Hate Speech and Targeted Campaigns<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Between July 1 and December 31, 2025, we observed coordinated campaigns across various platforms targeting political activists and civil society. These campaigns typically involved groups of social media users, particularly on X (formerly Twitter), targeting well-known figures with threats of death or sexual violence.<\/span><\/p>\n<h4><b>Impersonation Tactics<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Attackers utilized impersonation to identify and compromise users in contact with credible entities. This was not limited to media outlets but extended to humanitarian sectors:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Media and Citizen Journalists: Creating fake Instagram accounts or Telegram channels using slight variations in Latin character spelling.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Charitable Organizations: Several charities were similarly targeted on Telegram and Instagram to map their networks of supporters and beneficiaries.<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5907\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Harmful-Content-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h4><b>Comparative Analysis: Doxing During Protests vs. War<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">While both the Dey protests and the Esfand war saw surges in doxing and hate speech despite internet shutdowns, the two periods exhibited substantial strategic differences:<\/span><\/p>\n<p><a href=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-scaled.png\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5908\" src=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-1024x512.png\" alt=\"\" width=\"750\" height=\"375\" srcset=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-1024x512.png 1024w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-300x150.png 300w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-768x384.png 768w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-1536x768.png 1536w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-2048x1024.png 2048w, https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2026\/04\/Content-Moderation-EN-1568x784.png 1568w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Nationwide Dey Protests (Late December 2025\u2013January 2026):<\/b><span style=\"font-weight: 400;\"> Doxing was primarily decentralized and provincial. Telegram channels and Instagram accounts published phone numbers, home addresses, and workplace locations of protesters to incite local-level harassment.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Esfand War (February\u2013March 2026):<\/b><span style=\"font-weight: 400;\"> Following U.S. and Israeli military actions, the focus shifted to a national level. Regime officials publicly threatened diaspora activists with property confiscation and revocation of citizenship for supporting humanitarian intervention. This was followed by a wave of information exposure targeting these activists across social networks.<\/span><\/li>\n<\/ul>\n<h4><b>Involvement of Official Media<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">A significant development during the war period was the direct involvement of official and semi-official media in doxing efforts:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Tabnak:<\/b><span style=\"font-weight: 400;\"> The official Tabnak Telegram channel was directly involved in targeting civil society activists outside of Iran.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Mehr News Agency:<\/b><span style=\"font-weight: 400;\"> The official account of Mehr News Agency was locked by platform after it published the private address of actress Leila Otadi in Dubai.<\/span><\/li>\n<\/ul>\n<h4><b>Policy Enforcement on Platform X<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Following February 27, 2026, platform X implemented a visible policy shift, enforcing content moderation more strictly against users promoting the policies of the Islamic Republic. Significant removals included:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Mehr News Agency:<\/b><span style=\"font-weight: 400;\"> Accounts related to the outlet were removed following the publication of private information (doxing).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Regime Officials:<\/b><span style=\"font-weight: 400;\"> Accounts of several current officials, including Members of Parliament, were removed for supporting the Islamic Revolutionary Guard Corps (IRGC).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>High-Profile Pro-Regime Users:<\/b><span style=\"font-weight: 400;\"> Accounts were suspended for threatening supporters of the military actions against Iran.<\/span><\/li>\n<\/ul>\n<h4><b>Gender-Based Violence and Psychological Pressure<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">In both periods of repression, hate speech remained a primary tool for silencing dissent.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Nature of Threats:<\/b><span style=\"font-weight: 400;\"> Campaigns included severe cyberbullying, threats of murder, and gender-based violence, specifically targeting women with threats of rape.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Coerced Support:<\/b><span style=\"font-weight: 400;\"> High-follower accounts and well-known figures were targeted by organized campaigns designed to pressure them into publicly supporting the policies of the Islamic Republic.<\/span><b><br \/>\n<\/b><\/li>\n<\/ul>\n<h4><b>Indicators of Compromise<\/b><\/h4>\n<h5><b>Domains<\/b><\/h5>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">smtp3707.org<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">em557105.smtp3707.org<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">onlineviewer.net<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">confidential-mail.google.com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">cucps.k12.va.us<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">amazonses.com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">awstrack.me<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">joining-hosts-room.online<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">shorten.ee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">louisebatterseldom.com<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">gg.hls2.xyz<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">c978e75f17.adislran.info<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">c978e75f17.tc-spin.space<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">C978e75f17m.cs2-go.sbs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">c5acc344.geogo.cfd<\/span><\/li>\n<\/ul>\n<h5><b>Telegram Accounts and Bots<\/b><\/h5>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">@AuthenticatorBot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">@abdallahsarayra06<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">@mnzd12300<\/span><\/li>\n<\/ul>\n<h5><b>IP Addresses<\/b><\/h5>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">84.32.84.32<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">103.2.141.104<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">87.248.110.82<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">76.223.140.188<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">91.195.240.19<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">178.16.55.182<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">93.118.101.248<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">188.136.187.113<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">209.85.220.65<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">209.85.220.41<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">188.114.96.3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">188.114.97.3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">94.182.115.210<\/span><\/li>\n<\/ul>\n<h5><b>Uniform Resource Locator (URL)<\/b><\/h5>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">https:\/\/shorten.ee\/@help_center_6639<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">https:\/\/t.ly\/lZ6bU<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">awstrack.me<\/span><\/li>\n<\/ul>\n<h5><b>File Hashes<\/b><\/h5>\n<p><b>PDF.apk<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MD5: 873e3f275340fa1706b8e32026e6bedc<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SHA1: 71b8262e239869d74cd84eb5632abcfb252dc79d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SHA256: 7ef0da4c8bd83a5eaaa4a250d027b4ffc168206923d9453f81b02454f58ab020<\/span><\/p>\n<p><b>Vision-3187.apk<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MD5: deae9dae9c418c2db3575c9f91823eb9<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SHA1: 7201a304a4e90ea14af6e6bd4eef6a6965cae613<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SHA256: 33dfa923c2047098170ca5ebdaa25494707dd2e77873be46f07851b60ea982b2<\/span><\/p>\n<p><b>Pdf-812.apk<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MD5: 4044E8EAA4548C72A41705386632FC61<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SHA1: 66D5906CF5EBB54C4CDC5FCA65BBB6D8EC9DD694<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SHA256: 3D6136E5CC81837B77B12FA73989C23A23F8F68E5CEEF304BA9097FB734B47C4<\/span><\/p>\n<h5><b>Package Names<\/b><\/h5>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">com.chvi.pool<\/span><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Executive Summary and Trends The third installment of the Iran Cyber Threats report series has been published following a delay caused by the rapid developments of the Dey protests (late December 2025\u2013January 2026) and escalating military tensions. Given the sensitivity of this period and the emergence of new threat patterns, the data collection for this<a class=\"more-link\" href=\"https:\/\/filter.watch\/english\/2026\/04\/02\/cyber-threat-intelligence-report-july-2025-to-march-2026\/\">Continue reading <span class=\"screen-reader-text\">\"From Massacre to War;  Escalation of Cyber and Transnational Repression Amidst Digital Blackout\"<\/span><\/a><\/p>\n","protected":false},"author":13,"featured_media":5910,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[113],"tags":[365,364,366,300,367,363],"class_list":["post-5895","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-threat-reports","tag-cyber-attacks-on-journalists","tag-cybersecurity-iran-activists","tag-digital-surveillance-iran","tag-iran-cyber-threats","tag-iran-internet-blackout","tag-transnational-repression","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts\/5895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/comments?post=5895"}],"version-history":[{"count":4,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts\/5895\/revisions"}],"predecessor-version":[{"id":5914,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts\/5895\/revisions\/5914"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/media\/5910"}],"wp:attachment":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/media?parent=5895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/categories?post=5895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/tags?post=5895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}