Sign in

Nariman Gharib

@nariman.bsky.social
183 followers 20 following 73 posts

Britain-based Iranian Activist 🚦 Cyber Espionage Investigator 👁

PostsRepliesMedia
Nariman Gharib @nariman.bsky.social · 26/06/2026
www.iranintl.com/en/202606267... ..Amir Barati..
iranintl.com
Iranian wanted in US over IRGC-linked hacking case arrested in Montenegro
Montenegrin police and the FBI have arrested an Iranian national wanted by the United States over a major hacking campaign that allegedly targeted US universities and benefited Iran’s Revolutionary Gu...
000
Nariman Gharib @nariman.bsky.social · 22/05/2026
Cheshm-e Oghab is a free app for Iranians: aggregates Persian and international news,auto-translates foreign coverage, and surfaces stories users submit through Telegram and (X) feeds. It runs on independent support. If you know someone who'd find it useful,please share cheshmehoghab.app/en/support/
cheshmehoghab.app
Keep us on the air - Eagle Eye
Eagle Eye stays on the air thanks to people around the world. No company, no government, no ads. Only you.
000
Nariman Gharib @nariman.bsky.social · 07/05/2026
my new app for Iran. cheshmehoghab.app/en/
cheshmehoghab.app
Eagle Eye
Eagle Eye: eyes on the free world for 92 million Iranians, via satellite TV. No internet required.
000
Nariman Gharib @nariman.bsky.social · 23/03/2026
One of the safe houses of the IRGC Cyber Division HQ on Malekloo Street, Tehran, opposite Iran University of Science and Technology, was hit by a US and Israeli missile strike today This is the same facility from which Seyyed Ali Aghamiri, Yaser Balaghi, and Masoud Jalili launched phishing attacks.
000
Nariman Gharib @nariman.bsky.social · 22/03/2026
Two years ago I had published this video. On March 4th, this target in Tehran was struck with a missile.
100
Nariman Gharib @nariman.bsky.social · 19/03/2026
152
Nariman Gharib @nariman.bsky.social · 22/01/2026
Sadly, I informed all authorities including DuckDNS in December, but they didn't take it seriously and still haven't shut down either the server or the DuckDNS infrastructure.
000
Nariman Gharib @nariman.bsky.social · 09/12/2025
New from the Charming Kitten #APT35 leak: Payroll records exposing 35 IRGC cyber operatives with names, bank accounts, and salaries. Additional footage of the Kashef surveillance platform tracking Iranian citizens. And a classified 2004 document... blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Charming Kitten Leak Continues: Payroll Data and a Stolen IAEA Document
In my previous analyses of the Charming Kitten leak, I examined the organizational structure, target lists, financial infrastructure, and operational capabiliti...
123
Nariman Gharib @nariman.bsky.social · 09/12/2025
wait for it.
media.tenor.com
a computer screen with a netflix logo on the bottom
ALT: a computer screen with a netflix logo on the bottom
000
Nariman Gharib @nariman.bsky.social · 08/12/2025
#CK 194[.]76[.]226[.]226
000
Nariman Gharib @nariman.bsky.social · 03/12/2025
The Ministry of Intelligence of the Islamic Republic's cyber group "Banished Kitten", which is operating under the name "Handala", has gained access to Suvarnabhumi Airport (BKK). blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Exclusive: Handala's Thailand Blunder - MOIS Accidentally Exposes Access to Bangkok Airport
The cyber group "Banished Kitten," operating under the alias "Handala" and affiliated with the Ministry of Intelligence and Security of Iran (MOIS), has once ag...
010
Reposted by Nariman Gharib
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 01/12/2025
NEW: Europol shut down Cryptomixer, a crypto service alleged to have facilitated the laundering of 1.3 billion euros since 2016. Service was allegedly used by cybercriminals, drug and weapons traffickers, and ransomware gangs. techcrunch.com/2025/12/01/e...
techcrunch.com
European cops shut down crypto mixing website that helped launder 1.3 billion euros | TechCrunch
Europol announced the seizure of Cryptomixer’s official website, as well as 25 million euros and 12 terabytes of data from the mixer's service.
0107
Nariman Gharib @nariman.bsky.social · 26/11/2025
Today I am presenting the call logs from #APT35's IRGC-IO official VoIP services. This exclusive information was previously detailed in episode 4 of the KittenBusters series. - files.narimangharib.com/other/FanapT... - files.narimangharib.com/other/Custom...
010
Nariman Gharib @nariman.bsky.social · 24/11/2025
new blog post on #APT35 blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Department 40 Exposed: Inside the IRGC Unit Connecting Cyber Ops to Assassinations
A massive leak of internal documents has blown the cover off one of Iran's most active hacking groups. For years, the cybersecurity community tracked them as AP...
022
Nariman Gharib @nariman.bsky.social · 20/11/2025
Exposing the identity of "Unit 40" managers of IRGC intelligence; Tehran's largest espionage intelligence database #APT35 #CharmingKitten content.iranintl.com/unit40/index...
content.iranintl.com
افشای هویت مدیران «اداره ۴۰» اطلاعات سپاه؛بزرگترین بانک اطلاعاتی جاسوسی تهران
021
Nariman Gharib @nariman.bsky.social · 17/11/2025
Are you ready? Wait for new updates from the kittens. 😆
000
Nariman Gharib @nariman.bsky.social · 28/10/2025
New Charming Kitten APT35 leak shows their entire budget. Bitcoin payments for domains and hosting, ProtonMail accounts (still active, I checked), Iranian shell companies, the whole operation running on maybe $10k.
blog.narimangharib.com
Episode 4: Inside Charming Kitten's Financial Operations and Infrastructure Network
The fourth release of leaked documents from Iran's APT35 (Charming Kitten) operation exposes something previous leaks haven't: the complete financial backbone a...
153
Nariman Gharib @nariman.bsky.social · 23/10/2025
www.iranintl.com/202510230171
iranintl.com
حمله سایبری به آکادمی راوین؛ نشت گسترده اطلاعات دانشجویان آموزشگاه وزارت اطلاعات
پایگاه داده جامع حاوی اطلاعات شخصی دانشجویان آکادمی راوین، آموزشگاه مخفی وزارت اطلاعات که ایران‌اینترنشنال پیشتر هویت اعضای آن را افشا کرده بود، به صورت گسترده منتشر شده است.
000
Nariman Gharib @nariman.bsky.social · 23/10/2025
000
Nariman Gharib @nariman.bsky.social · 22/10/2025
Group-IB Threat Intelligence uncovered a sophisticated phishing campaign orchestrated by the Advanced Persistent Threat (APT) MuddyWater, targeting international organizations worldwide to gather foreign intelligence. www.group-ib.com/blog/muddywa... #RavinAcademy
group-ib.com
000
Nariman Gharib @nariman.bsky.social · 22/10/2025
A comprehensive database containing complete registration records of Ravin Academy students has been obtained by me, revealing detailed personal information of individuals enrolled in the organization's training programs. blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Exclusive: Full Student Database of MOIS-Affiliated Ravin Academy Leaked
Based on the intelligence assessments from multiple government agencies, Ravin Academy functions as a MOIS-directed recruitment and training front operating und...
100
Nariman Gharib @nariman.bsky.social · 18/10/2025
000
Nariman Gharib @nariman.bsky.social · 16/10/2025
BellaCiao was developed at Tehran's Shuhada base. Moses Staff & Sahyoun24 weren't independent—all run by the same IRGC unit. MORE... blog.narimangharib.com/posts/2025%2... #APT35
blog.narimangharib.com
Part two and three of the leaked Charming Kitten files reveal operations across five continents
In my previous analysis of the Charming Kitten leak, I examined the unprecedented breach that exposed the inner workings of an Iranian state-sponsored hacking o...
021
Nariman Gharib @nariman.bsky.social · 30/09/2025
Breaking News: Iranian Advanced Persistent Threat Group #APT35 Has Been Compromised, with Internal Documents Leaked Online blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Massive Leak Exposes Inner Workings of Iranian Hacking Group Charming Kitten
In what appears to be one of the most significant breaches of an Iranian state-sponsored hacking operation to date, an anonymous source has published internal d...
111
Reposted by Nariman Gharib
Joe Tidy BBC News @joetidy.bsky.social · 18/09/2025
BREAKING: Two teenagers charged over 'Scattered Spider' Transport for London cyber attack. About to appear in court for first time. I'm here for BBC so follow the story for updates: www.bbc.co.uk/news/article...
bbc.co.uk
Teenagers charged over Transport for London cyber attack
Thalha Jubair, 19, from East London, and Owen Flowers, 18, from Walsall in the West Midlands, were arrested
1105
Nariman Gharib @nariman.bsky.social · 13/09/2025
www.international.gc.ca/transparency...
international.gc.ca
Iran-linked hacker group doxes journalists and amplifies leaked information through AI chatbots
Rapid Response Mechanism Canada (RRM Canada) has detected a “hack and leak” operation by Iran-linked hacker group, “Handala Hack Team” (Handala). The operation targeted five Iran International journal...
000
Nariman Gharib @nariman.bsky.social · 10/09/2025
It's truly enjoyable to see the efforts of the Islamic Republic's cyber forces as they try to use social engineering on me.
000
Reposted by Nariman Gharib
SentinelOne @sentinelone.com · 04/09/2025
Your cyber threat intel is part of the North Korean strategy: DPRK operators are abusing CTI platforms to see if they’ve been seen—and moving faster because of it. 👀
178
Reposted by Nariman Gharib
Raphael Satter @raphae.li · 04/09/2025
Granular look here from @ajvicens.bsky.social and I on how job seekers in the crypto currency industry are being bombarded with fake job offers from North Korean hackers. Based on 19 interviews with targets and research from cyber firms @sentinelone.com and Validin www.reuters.com/world/asia-p...
reuters.com
Exclusive: How North Korean hackers are using fake job offers to steal cryptocurrency
North Korean hackers are saturating the cryptocurrency industry with credible-sounding job offers as part of their campaign to steal digital cash, according to new research, raw data, and interviews.
074
Nariman Gharib @nariman.bsky.social · 03/09/2025
🤣🤣🤣🤣🤣🤣
100
Reposted by Nariman Gharib
Cloudflare @cloudflare.social · 02/09/2025
A recent security issue announced by Salesloft has impacted many companies, including Cloudflare. Read more blog.cloudflare.com/response-to-sal…
blog.cloudflare.com
The impact of the Salesloft Drift breach on Cloudflare and our customers
An advanced threat actor, GRUB1, exploited the integration between Salesloft’s Drift chat agent and Salesforce to gain unauthorized access to Salesforce tenants of Cloudflare and many other companies.
2125
Reposted by Nariman Gharib
Catalin Cimpanu @campuscodi.risky.biz · 02/09/2025
A UK government study has found that, despite being aware that cyber insurance exists and is an option, most British companies struggle to understand insurance policy details, which is impeding a broader adoption www.gov.uk/government/p...
293
Nariman Gharib @nariman.bsky.social · 29/08/2025
Screw it, unlocking the paywall on my Charming Kitten investigation. Everyone should know how they're impersonating former Pentagon officials to target activists. Full technical details, IoCs, everything that was VIP-only is free now vip.narimangharib.com/charming-kit... #APT35
vip.narimangharib.com
Charming Kitten 2025: Strategic Target Selection and Researcher Surveillance Analysis
Overview This research examines a new Charming Kitten campaign utilizing advanced impersonation tactics, long-term monitoring of security researchers, and unique infrastructure. This analysis is base...
054
Nariman Gharib @nariman.bsky.social · 28/08/2025
The Islamic Republic is floating the idea of unblocking Telegram again blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
The Telegram Trap: Why Iran's
The Islamic Republic is floating the idea of unblocking Telegram again, and if you believe this is about digital freedom, I have a bridge in Tehran to sell you....
000
Nariman Gharib @nariman.bsky.social · 22/08/2025
LabDookhtegan paralyzed 64 Iranian ships at sea last night, again... blog.narimangharib.com/posts/2025%2... #Iran #CyberAttack
blog.narimangharib.com
Inside the Lab-Dookhtegan Hack: How Iranian Ships Lost Their Voice at Sea
Lab-Dookhtegan has been systematically targeting Iranian infrastructure for months now, and when they reached out about their latest operation, I knew it would ...
100
Reposted by Nariman Gharib
Bellingcat @bellingcat.com · 14/08/2025
In May, we, alongside CBC's Visual Investigation Unit, @tjekdet.dk and @politiken.dk revealed the identity of the key administrator behind one of the largest AI porn sites. Dutch politicians across political parties are now calling for the Canadian to be extradited. www.cbc.ca/news/canada/...
cbc.ca
Dutch politicians join calls to extradite Canadian behind notorious AI porn site | CBC News
Politicians from a second European country are calling for the extradition of the Canadian man behind a notorious, pornographic website which featured deepfake images and videos of celebrities, politi...
517579
Nariman Gharib @nariman.bsky.social · 14/08/2025
Iran's defense sector offers $213,000 prize for counter-drone technology, seeking systems to detect and neutralize small UAVs through jamming, AI tracking, or physical interception. Competition highlights Tehran's push for indigenous anti-drone capabilities hxxps://archive[.]is/qCyIt
010
Nariman Gharib @nariman.bsky.social · 13/08/2025
Tonight, Iran International TV exposed the identity of a Handala hacking group admin—part of the Banished Kitten cyber unit I've previously reported on—and unmasked his handler in Iran's Ministry of Intelligence. - Morteza Aftabi-Far - Ali Bermoudeh
1143
Nariman Gharib @nariman.bsky.social · 09/08/2025
011
Nariman Gharib @nariman.bsky.social · 07/08/2025
blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
New Charming Kitten Campaign Impersonating Pentagon Officials
The Charming Kitten group has launched a new tactic for targeting Iranian activists. Instead of creating fake identities, they're now directly impersonating a s...
111
Nariman Gharib @nariman.bsky.social · 24/07/2025
Remember his name: Hesam Roshani. #APT39
023
Nariman Gharib @nariman.bsky.social · 19/07/2025
Iranian 'security firm' #Amnban targeted 17+ global airlines in state-sponsored espionage. CEO hired US/FBI-sanctioned hacker, built shadow infrastructure with dozens of fake emails worldwide. Full story with leaked internal documents: blog.narimangharib.com/posts/2025%2... #APT39
blog.narimangharib.com
The Amnban Files: Inside Iran's Cyber-Espionage Factory Targeting Global Airlines
They called themselves cybersecurity experts. They're actually Tehran's digital hit squad.Someone handed me the keys to the kingdom—gigabytes of data ripped f...
054
Nariman Gharib @nariman.bsky.social · 16/07/2025
#APT39
001
Nariman Gharib @nariman.bsky.social · 24/06/2025
blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Burned Money, Hidden Wallets: Inside the IRGC's $800 Million Crypto Pipeline Through Nobitex
What if the June 18, 2025 cyberattack on Iran's largest cryptocurrency exchange wasn't really about destroying $90 million in digital assets, but rather about e...
010
Reposted by Nariman Gharib
Joe Tidy BBC News @joetidy.bsky.social · 15/05/2025
Exclusive: 'They yanked their own plug': how Co-op averted an even worse cyber attack. Details sent to me by the angry Co-op hackers shows quick thinking from Co-op staff narrowly averted a full ransomware attack. www.bbc.co.uk/news/article...
bbc.co.uk
Co-op narrowly avoided an even worse cyber attack, BBC learns
The revelation - from the criminals responsible - explains why the Co-op is getting back to business faster than M&S.
3338
Reposted by Nariman Gharib
Joseph Cox @josephcox.bsky.social · 28/04/2025
New from 404 Media: the age of realtime deepfake fraud is here. Scammers in Nigeria are using realtime deepfakes to change their race, facial hair, gender, more to appear as someone else on video calls. Results very realistic now. Also tricking verification systems www.404media.co/the-age-of-r...
404media.co
The Age of Realtime Deepfake Fraud Is Here
Fraudsters are able to change their race, facial hair, voice, and more during live video calls with very little effort. Scammers are already fooling the elderly and verification systems.
9282166
Nariman Gharib @nariman.bsky.social · 14/04/2025
Major Data Breach at #Iran's Largest Mobile Operator (MCI) Exposes 30 Million Customers' Personal Information blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Major Data Breach at Iran's Largest Mobile Operator (MCI) Exposes 30 Million Customers' Personal Information
In another major security incident affecting Iran's telecommunications sector, hackers have gained access to the customer database of Mobile Communication Company of Iran (MCI), also known as Hamrah-e...
000
Nariman Gharib @nariman.bsky.social · 13/04/2025
Exciting updates are on the way! I’ll soon be sharing exclusive, special content with you. Please note that some topics will no longer be shared publicly moving forward. Thank you for your continued support and understanding!
vip.narimangharib.com
Nariman Gharib
Investigating cyber threats and electronic activities of the Iranian regime. Detailed insights into cyber units, security analysis, and tools for combating internet censorship.
000
Nariman Gharib @nariman.bsky.social · 10/04/2025
No caption needed.
000