Iran’s Intelligence Group 13 – DomainTools Investigations | DTI

Iran’s Intelligence Group 13 – DomainTools Investigations | DTI

Intelligence Group 13 is a key operational unit within Iran’s IRGC cyber command, integrating cyber-espionage, sabotage, and psychological warfare to conduct hybrid operations against adversaries. This group leverages a complex ecosystem of front companies and propaganda arms like CyberAveng3rs to execute covert intrusions, influence campaigns, and asymmetric retaliation targeting critical infrastructure and public perception. #IntelligenceGroup13 #CyberAveng3rs #ShahidKavehGroup #IRGCCyberCommand

Keypoints

  • Intelligence Group 13 operates under the Shahid Kaveh Cyber Group within the IRGC, combining cyber offensive capabilities with ideological and psychological warfare.
  • The IRGC cyber command structure includes multiple divisions: Electronic Warfare and Cyber Defense Organization (EWCD), Intelligence Organization (IO), and Quds Force units, which jointly support Intelligence Group 13 operations.
  • The group’s tactics focus on targeting industrial control systems in the U.S. and Israel, pre-positioning malware, credential theft, and disseminating psychological warfare via CyberAveng3rs propaganda outlets.
  • CyberAveng3rs acts as a media and propaganda front for Intelligence Group 13, amplifying threats, publicizing operations, and issuing pre- and post-attack narratives via Telegram and Instagram.
  • The IRGC maintains an extensive contractor and front company network (e.g., Emen Net Pasargad, Mahak Rayan Afraz, Afkar Systems) to provide technical support, talent recruitment, and plausible deniability.
  • Frequent rebranding and leadership overlap among these companies ensure operational resilience despite sanctions and exposure.
  • Future operations are expected to integrate cyber-kinetic attacks with narrative manipulation targeting critical infrastructure and public trust in the U.S., Israel, and Gulf states.

MITRE Techniques

  • [T1078] Valid Accounts – Intelligence Group 13 uses credential theft to gain and maintain access (“credential harvesting”).
  • [T1590] Gather Victim Network Information – Conducts OSINT harvesting to support intrusion planning and targeting.
  • [T1204] User Execution – Executes phishing campaigns for initial access to target systems.
  • [T1550] Use of Alternate Authentication Material – Deploys pre-positioned malware implants for later activation.
  • [T1499] Endpoint Denial of Service – Disrupts critical infrastructure such as water treatment and fuel systems (“disruptive sabotage of critical infrastructure”).
  • [T1566] Phishing – Uses phishing to obtain credentials and facilitate network infiltration.
  • [T1071] Application Layer Protocol – Utilizes Telegram and Instagram platforms for information dissemination and psychological operations.
  • [T1140] Deobfuscate/Decode Files or Information – Leverages malware control panels and implants to manage covert operations (“malware control panel captures”).

Indicators of Compromise

  • [Domain] Propaganda and tribute site – kaveh313.lxb.ir (archived site associated with group’s ideological framework)
  • [Telegram Channel] CyberAveng3rs – Used for propaganda dissemination and operational taunts against Western and Israeli targets.
  • [Instagram Handle] @mr.sul.ir – Platform for leaking screenshots and issuing psychological warfare content.
  • [File Hash – Malware] Examples of implants such as IOControl and Project Binder associated with Intelligence Group 13 (mentioned in context with sabotage tools).
  • [Company Names] Emen Net Pasargad, Ayandeh Sazan Sepehr Aria – Front companies involved in IRGC cyber operations and information warfare.
  • [Company Names] Mahak Rayan Afraz, Afkar Systems – Contractors linked to surveillance and offensive cyber tools, including AI platforms and ICS tools.


Read more: https://dti.domaintools.com/irans-intelligence-group-13/