{"id":37184,"date":"2020-09-17T23:41:21","date_gmt":"2020-09-17T23:41:21","guid":{"rendered":"http:\/\/2125069f-fba6-410d-8e1d-8a835739f5ee"},"modified":"2020-09-17T23:41:21","modified_gmt":"2020-09-17T23:41:21","slug":"us-sanctions-iranian-government-front-company-hiding-major-hacking-operations","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/","title":{"rendered":"US sanctions Iranian government front company hiding major hacking operations"},"content":{"rendered":"<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2020\/02\/21\/61cd0415-243f-4b02-9cfa-7e7f55872c85\/iranian-hackers-have-been-hacking-vpn-se-5e4e92c9db1d010001ac4677-1-feb-21-2020-21-08-22-poster.jpg\" class alt=\"iranian-hackers-have-been-hacking-vpn-se-5e4e92c9db1d010001ac4677-1-feb-21-2020-21-08-22-poster.jpg\"><\/span><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<p><strong>The US government has imposed sanctions today on a front company that hid a massive hacking operation perpetrated by the Iranian government against its own citizens, foreign companies, and governments abroad.<\/strong><\/p>\n<p>Sanctions were imposed on the &#8220;<strong>Rana Intelligence Computing Company<\/strong>,&#8221; also known as the Rana Institute, or Rana, as well as&nbsp;<a href=\"https:\/\/home.treasury.gov\/policy-issues\/financial-sanctions\/recent-actions\/20200917\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">45 current and former employees<\/a>, such as managers, programmers, or hacking experts.<\/p>\n<p>US officials said Rana operated as a front for the Iranian Ministry of Intelligence and Security (MOIS). Rana&#8217;s main duties were to mount national and international hacking campaigns.<\/p>\n<p>Through its local operations, Rana helped the government monitor Iranian citizens, dissidents, journalists, former government employees, environmentalists, refugees, students, professors, and anyone considered a threat for the local regime.<\/p>\n<p>Externally, Rana also hacked the government networks of neighboring countries, but also foreign companies in the travel, academic, and telecommunications sectors. Officials said Rana used the access to the hacked foreign companies to track individuals whom the MOIS considered a threat.<\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/\" class=\"lazy\" alt=\"rana-graph.png\" data-original=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2020\/09\/17\/1e9cc95a-89fa-4ce2-bc86-924f7190c653\/rana-graph.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2020\/09\/17\/1e9cc95a-89fa-4ce2-bc86-924f7190c653\/rana-graph.png\" class alt=\"rana-graph.png\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><span class=\"credit\"> Image: US Treasury Department <\/span><\/figcaption><\/figure>\n<p>Across the years, Rana&#8217;s hacking operations left a long trail of clues that cyber-security firms traced back to Iran.<\/p>\n<p>Investigations into these past Rana-linked operations can be found in cyber-security reports about the activities of a hacking group known as&nbsp;<a href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/actor\/apt39\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\"><strong>APT39<\/strong><\/a>, or Chafer, Cadelspy, Remexi, and ITG07 \u2014 all different names given by different security firms, but referring to the same threat actor, in this case, Rana.<\/p>\n<h3>Rana exposed in May 2019<\/h3>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>However, for a long time, nobody even knew that Rana existed, let alone that it was a front company for APT39 and the Iranian regime.<\/p>\n<p>The first time the world heard about Rana was in a&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/new-leaks-of-iranian-cyber-espionage-operations-hit-telegram-and-the-dark-web\/\" target=\"_blank\" rel=\"noopener noreferrer\">ZDNet article<\/a>&nbsp;published in May 2019, documenting the leak of confidential information pertaining to Iranian hacking groups.<\/p>\n<p>At the time, shadowy entities leaked the source code of APT34 malware, data about MuddyWater server backends, and snippets from internal Rana documents labeled as &#8220;secret.&#8221;<\/p>\n<p>&#8220;These [Rana] documents contain lists of victims, cyber-attack strategies, alleged areas of access, a list of employees, and screenshots from internal websites relevant to espionage systems,&#8221; Israeli cyber-security firm ClearSky said in a&nbsp;<a href=\"https:\/\/www.clearskysec.com\/wp-content\/uploads\/2019\/05\/Iranian-Nation-State-APT-Leak-Analysis-and-Overview.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">report<\/a>&nbsp;published in May 2019.<\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/\" class=\"lazy\" alt=\"Iran Rana leak on the clear web\" height=\"auto\" width=\"1200\" data-original=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2019\/05\/09\/3f79798a-172f-4046-960c-db6f5c09e353\/resize\/1200xauto\/4f87d02054042aeac035411247355be2\/iran-clear-web.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2019\/05\/09\/3f79798a-172f-4046-960c-db6f5c09e353\/resize\/1200xauto\/4f87d02054042aeac035411247355be2\/iran-clear-web.png\" class alt=\"Iran Rana leak on the clear web\" height=\"auto\" width=\"1200\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><span class=\"credit\"> Image: ZDNet <\/span><\/figcaption><\/figure>\n<p>At the time, the Rana leak was considered odd because it didn&#8217;t fit with the other two.<\/p>\n<p>The first two leaks \u2014APT34 and MuddyWater\u2014 were two very well-known Iranian hacking groups.<\/p>\n<p>On the other hand, Rana was described as a mere government contractor.&nbsp;<\/p>\n<p>At the time, security firms suspected that Rana was also an Iranian APT (advanced persistent threat), but noone could link Rana to any known group.<\/p>\n<p>This mystery was solved today. In press releases by the&nbsp;<a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sm1127\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">US Department of Treasury<\/a>&nbsp;and the&nbsp;<a href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\/boston\/news\/press-releases\/fbi-releases-cybersecurity-advisory-on-previously-undisclosed-iranian-malware-used-to-monitor-dissidents-and-travel-and-telecommunications-companies\/layout_view\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Federal Bureau of Investigations<\/a>, the US government has formally linked Rana to APT39 and the MOIS for the first time.<\/p>\n<p>This official link now allows for the contractor&#8217;s full spectrum of hacks to come into the limelight. And according to US officials, some of these operations might have crossed the line from intelligence gathering to human rights abuses, such as unwarranted arrests, followed by physical and psychological intimidation by MOIS agents.<\/p>\n<p>Today&#8217;s sanctions prohibit US companies from doing business with Rana and its 45 current or former employees.<\/p>\n<p>At the same time with today&#8217;s sanctions, the FBI has also issued a&nbsp;<a href=\"https:\/\/www.documentcloud.org\/documents\/7212588-FBI-PIN-APT39.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">private industry notification (PIN)<\/a>&nbsp;with eight separate and distinct sets of malware used by Rana (MOIS) to conduct their computer intrusion activities.<\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/\" class=\"lazy\" alt=\"rana-fbi-pin.png\" data-original=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/09\/17\/55157bcd-1e11-4b9a-bf74-5ec648d8d355\/rana-fbi-pin.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/09\/17\/55157bcd-1e11-4b9a-bf74-5ec648d8d355\/rana-fbi-pin.png\" class alt=\"rana-fbi-pin.png\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<h3>Iranian week<\/h3>\n<p>The APT39 sanctions are just the latest in a long series of actions the US has prepared against Iranian entities this week. Previously this week, the DOJ also charged:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.zdnet.com\/article\/us-charges-two-hackers-for-defacing-us-websites-following-soleimani-killing\/\" target=\"_blank\" rel=\"noopener noreferrer\">an Iranian hacker<\/a>&nbsp;on Tuesday for defacing US websites following the US killing of an Iranian military general;<\/li>\n<li><a href=\"https:\/\/www.zdnet.com\/article\/us-charges-two-iranian-hackers-for-years-long-cyber-espionage-cybercrime-spree\/\" target=\"_blank\" rel=\"noopener noreferrer\">two hackers<\/a>&nbsp;on Wednesday for orchestrating a years-long hacking campaign at the behest of the Iranian government, but also for their own personal financial gains;<\/li>\n<li><a href=\"https:\/\/www.zdnet.com\/article\/us-charges-iranian-hackers-for-breaching-us-satellite-companies\/\" target=\"_blank\" rel=\"noopener noreferrer\">three Iranians<\/a>&nbsp;today, Thursday, for hacking aerospace and satellite companies in the US.<\/li>\n<\/ul>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>US says the Iranian government used the &#8220;Rana Intelligence Computing Company&#8221; as a front for the APT39 hacking group.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":37185,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-37184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>US sanctions Iranian government front company hiding major hacking operations 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"US sanctions Iranian government front company hiding major hacking operations 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-17T23:41:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/09\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"540\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"US sanctions Iranian government front company hiding major hacking operations\",\"datePublished\":\"2020-09-17T23:41:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/\"},\"wordCount\":678,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/\",\"name\":\"US sanctions Iranian government front company hiding major hacking operations 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg\",\"datePublished\":\"2020-09-17T23:41:21+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg\",\"width\":960,\"height\":540},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"US sanctions Iranian government front company hiding major hacking operations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"US sanctions Iranian government front company hiding major hacking operations 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/","og_locale":"en_US","og_type":"article","og_title":"US sanctions Iranian government front company hiding major hacking operations 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-09-17T23:41:21+00:00","og_image":[{"width":960,"height":540,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/09\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"US sanctions Iranian government front company hiding major hacking operations","datePublished":"2020-09-17T23:41:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/"},"wordCount":678,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/09\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/","url":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/","name":"US sanctions Iranian government front company hiding major hacking operations 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/09\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg","datePublished":"2020-09-17T23:41:21+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/09\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/09\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations.jpg","width":960,"height":540},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/us-sanctions-iranian-government-front-company-hiding-major-hacking-operations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"US sanctions Iranian government front company hiding major hacking operations"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=37184"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37184\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/37185"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=37184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=37184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=37184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}