# Iran Ministry of Intelligence

> As of 2026-09-27, Iran Ministry of Intelligence is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as Security. ATT&CK coverage spans 32 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1057 (Process Discovery), T1082 (System Information Discovery).

- **Nation:** Iran
- **Tracked threats:** 2
- **Categories:** MALWARE
- **Also known as:** Security
- **As of:** 2026-09-27

## ATT&CK techniques observed

32 techniques observed across 2 of 2 tracked threats. Tactics: Collection (7), Stealth (formerly Defense Evasion) (5), Command and Control (4), Execution (3), Discovery (2), Exfiltration (2).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1090.002](https://intel.threadlinqs.com/technique/T1090.002) External Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1102.002](https://intel.threadlinqs.com/technique/T1102.002) Bidirectional Communication — Command and Control — observed in 2 of 2 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 2 tracked threats
- [T1123](https://intel.threadlinqs.com/technique/T1123) Audio Capture — Collection — observed in 2 of 2 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 2 of 2 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 2 of 2 tracked threats
- [T1547.001](https://intel.threadlinqs.com/technique/T1547.001) Registry Run Keys / Startup Folder — Persistence — observed in 2 of 2 tracked threats
- [T1566.003](https://intel.threadlinqs.com/technique/T1566.003) Phishing — Initial Access — observed in 2 of 2 tracked threats
- [T1567.002](https://intel.threadlinqs.com/technique/T1567.002) Exfiltration to Cloud Storage — Exfiltration — observed in 2 of 2 tracked threats
- [T1585.001](https://intel.threadlinqs.com/technique/T1585.001) Establish Accounts — Resource Development — observed in 2 of 2 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 2 of 2 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 2 tracked threats

## Tracked threats

- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — HIGH
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2526) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence
