Researchers: Iran's cyber army, or Cyberi, ramped up spear-phishing and adopted new tactics aiming to sow distrust among citizens as political unrest continues
Arian Khameneh / Wired :
Context & Ripple Effects
This 2023 report on Cyberi sits at the hinge of a documented escalation arc: Iran's cyberwar with Israel had already been hitting civilians on both sides via fuel-system and dating-site attacks by late 2021, and Check Point later detailed a monthslong espionage campaign against rivals like Israel showing the same apparatus maturing. What the Wired reporting adds is the inward turn — the same cyber army pivoting from external espionage to spear-phishing its own citizens during unrest.
First-order effects
- Iranian citizens under political unrest are the direct target: Cyberi's spear-phishing is designed to manufacture distrust among them, making the population itself the operational objective rather than a bystander.
Second-order effects
- The influence operation works alongside the [[a:1163504|surveillance capabilities researchers say Iran has integrated across its communications networks]] and used to track protesters — phishing seeds distrust while surveillance identifies who acts on it.
Third-order effects
- The pattern across this coverage — external espionage, hacktivist retaliation like Predatory Sparrow's Bank Sepah attack, and later full mobilization of Iranian hackers to sow chaos and find targets — points toward cyber units becoming regime-stability instruments, where the line between foreign cyberwar and domestic information control effectively disappears.
The trend: Iran's cyber operations are fusing domestic influence campaigns with foreign espionage, turning a single state cyber apparatus into a tool of both external conflict and internal control.