CSIDB logo
Threat actor

Iranian State-Sponsored Actors

Attribution profile

Type
Nation State
Location
Iran
Known incidents
1 incident
First seen
2017-06-23
Last seen
2017-06-23
Updated
2026-07-31 08:05
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Iranian State-Sponsored Actors operates under that alias and is believed to be based in Iran. Public reporting attributes the group to the Iranian government, describing its activities as state-sponsored. The actor has been linked to cyber operations that target governmental institutions abroad. In the incident described by British intelligence, the actor was identified as responsible for a brute-force campaign against the email accounts of United Kingdom parliamentarians. The attack occurred on 23 June 2017 and affected dozens of members of parliament, including the prime minister and senior ministers.

The targeting observed in this operation focused on the United Kingdom’s political sector, specifically the parliamentary email system used for constituent communications. The actors sought to gain unauthorized access to accounts protected by weak passwords, exploiting credential weaknesses rather than deploying malware. The strategic aim, as stated in the source material, was to obtain entry to the email accounts themselves, which could enable the monitoring of correspondence. No explicit financial motive was mentioned in the reporting; the emphasis was on the breach of a government communications channel. The incident highlighted the vulnerability of public‑sector email systems to credential‑based attacks.

Regarding tactics, techniques and procedures, the only method referenced in the reporting is a brute‑force attack that guessed passwords to compromise accounts. No specific malware families, exploit kits, or custom tooling were described in the source material. The initial access vector consisted of repeated login attempts against the parliamentary email service until valid credentials were found. The actor’s affiliation with the Iranian state was asserted by British intelligence, which dismissed earlier suspicions of Russian or North Korean involvement. The June 2017 parliamentary email breach stands as the publicly reported operation that exemplifies the actor’s use of state‑backed credential‑guessing tactics against a Western government target.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB