Sign in

Nariman Gharib

@nariman.bsky.social
183 followers 20 following 73 posts

Britain-based Iranian Activist 🚦 Cyber Espionage Investigator 👁

PostsRepliesMedia
Nariman Gharib @nariman.bsky.social · 26/06/2026
www.iranintl.com/en/202606267... ..Amir Barati..
iranintl.com
Iranian wanted in US over IRGC-linked hacking case arrested in Montenegro
Montenegrin police and the FBI have arrested an Iranian national wanted by the United States over a major hacking campaign that allegedly targeted US universities and benefited Iran’s Revolutionary Gu...
000
Nariman Gharib @nariman.bsky.social · 22/05/2026
Cheshm-e Oghab is a free app for Iranians: aggregates Persian and international news,auto-translates foreign coverage, and surfaces stories users submit through Telegram and (X) feeds. It runs on independent support. If you know someone who'd find it useful,please share cheshmehoghab.app/en/support/
cheshmehoghab.app
Keep us on the air - Eagle Eye
Eagle Eye stays on the air thanks to people around the world. No company, no government, no ads. Only you.
000
Nariman Gharib @nariman.bsky.social · 07/05/2026
my new app for Iran. cheshmehoghab.app/en/
cheshmehoghab.app
Eagle Eye
Eagle Eye: eyes on the free world for 92 million Iranians, via satellite TV. No internet required.
000
Nariman Gharib @nariman.bsky.social · 23/03/2026
One of the safe houses of the IRGC Cyber Division HQ on Malekloo Street, Tehran, opposite Iran University of Science and Technology, was hit by a US and Israeli missile strike today This is the same facility from which Seyyed Ali Aghamiri, Yaser Balaghi, and Masoud Jalili launched phishing attacks.
000
Nariman Gharib @nariman.bsky.social · 22/03/2026
000
Nariman Gharib @nariman.bsky.social · 22/03/2026
Two years ago I had published this video. On March 4th, this target in Tehran was struck with a missile.
100
Nariman Gharib @nariman.bsky.social · 20/03/2026
😎
000
Nariman Gharib @nariman.bsky.social · 19/03/2026
152
Nariman Gharib @nariman.bsky.social · 22/01/2026
Sadly, I informed all authorities including DuckDNS in December, but they didn't take it seriously and still haven't shut down either the server or the DuckDNS infrastructure.
000
Nariman Gharib @nariman.bsky.social · 10/12/2025
Salary and wage report for members of the Charming Kitten (#APT35) cyber group in May 2025 based on current exchange rates. This report represents the operational costs of cyber operations against journalists, human rights activists, and political activists in Iran.
000
Nariman Gharib @nariman.bsky.social · 09/12/2025
New from the Charming Kitten #APT35 leak: Payroll records exposing 35 IRGC cyber operatives with names, bank accounts, and salaries. Additional footage of the Kashef surveillance platform tracking Iranian citizens. And a classified 2004 document... blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Charming Kitten Leak Continues: Payroll Data and a Stolen IAEA Document
In my previous analyses of the Charming Kitten leak, I examined the organizational structure, target lists, financial infrastructure, and operational capabiliti...
123
Nariman Gharib @nariman.bsky.social · 09/12/2025
wait for it.
media.tenor.com
a computer screen with a netflix logo on the bottom
ALT: a computer screen with a netflix logo on the bottom
000
Nariman Gharib @nariman.bsky.social · 08/12/2025
#CK 194[.]76[.]226[.]226
000
Nariman Gharib @nariman.bsky.social · 03/12/2025
The Ministry of Intelligence of the Islamic Republic's cyber group "Banished Kitten", which is operating under the name "Handala", has gained access to Suvarnabhumi Airport (BKK). blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Exclusive: Handala's Thailand Blunder - MOIS Accidentally Exposes Access to Bangkok Airport
The cyber group "Banished Kitten," operating under the alias "Handala" and affiliated with the Ministry of Intelligence and Security of Iran (MOIS), has once ag...
010
Reposted by Nariman Gharib
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 01/12/2025
NEW: Europol shut down Cryptomixer, a crypto service alleged to have facilitated the laundering of 1.3 billion euros since 2016. Service was allegedly used by cybercriminals, drug and weapons traffickers, and ransomware gangs. techcrunch.com/2025/12/01/e...
techcrunch.com
European cops shut down crypto mixing website that helped launder 1.3 billion euros | TechCrunch
Europol announced the seizure of Cryptomixer’s official website, as well as 25 million euros and 12 terabytes of data from the mixer's service.
0107
Nariman Gharib @nariman.bsky.social · 26/11/2025
Today I am presenting the call logs from #APT35's IRGC-IO official VoIP services. This exclusive information was previously detailed in episode 4 of the KittenBusters series. - files.narimangharib.com/other/FanapT... - files.narimangharib.com/other/Custom...
010
Nariman Gharib @nariman.bsky.social · 24/11/2025
new blog post on #APT35 blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Department 40 Exposed: Inside the IRGC Unit Connecting Cyber Ops to Assassinations
A massive leak of internal documents has blown the cover off one of Iran's most active hacking groups. For years, the cybersecurity community tracked them as AP...
022
Nariman Gharib @nariman.bsky.social · 20/11/2025
Exposing the identity of "Unit 40" managers of IRGC intelligence; Tehran's largest espionage intelligence database #APT35 #CharmingKitten content.iranintl.com/unit40/index...
content.iranintl.com
افشای هویت مدیران «اداره ۴۰» اطلاعات سپاه؛بزرگترین بانک اطلاعاتی جاسوسی تهران
021
Nariman Gharib @nariman.bsky.social · 17/11/2025
Are you ready? Wait for new updates from the kittens. 😆
000
Nariman Gharib @nariman.bsky.social · 29/10/2025
KittenBusters leaked #APT35 infrastructure docs. Using leaked passwords, I accessed their Edis Global accounts & downloaded invoices. They used phone numbers from Russia, Israel & Netherlands with fake addresses, paying via crypto. files.narimangharib.com/other/CK%20-...
021
Nariman Gharib @nariman.bsky.social · 28/10/2025
😀
100
Nariman Gharib @nariman.bsky.social · 28/10/2025
New Charming Kitten APT35 leak shows their entire budget. Bitcoin payments for domains and hosting, ProtonMail accounts (still active, I checked), Iranian shell companies, the whole operation running on maybe $10k.
blog.narimangharib.com
Episode 4: Inside Charming Kitten's Financial Operations and Infrastructure Network
The fourth release of leaked documents from Iran's APT35 (Charming Kitten) operation exposes something previous leaks haven't: the complete financial backbone a...
153
Nariman Gharib @nariman.bsky.social · 23/10/2025
www.iranintl.com/202510230171
iranintl.com
حمله سایبری به آکادمی راوین؛ نشت گسترده اطلاعات دانشجویان آموزشگاه وزارت اطلاعات
پایگاه داده جامع حاوی اطلاعات شخصی دانشجویان آکادمی راوین، آموزشگاه مخفی وزارت اطلاعات که ایران‌اینترنشنال پیشتر هویت اعضای آن را افشا کرده بود، به صورت گسترده منتشر شده است.
000
Nariman Gharib @nariman.bsky.social · 23/10/2025
000
Nariman Gharib @nariman.bsky.social · 22/10/2025
Ravin Academy confirmed the breach and published a statement.
000
Nariman Gharib @nariman.bsky.social · 22/10/2025
Group-IB Threat Intelligence uncovered a sophisticated phishing campaign orchestrated by the Advanced Persistent Threat (APT) MuddyWater, targeting international organizations worldwide to gather foreign intelligence. www.group-ib.com/blog/muddywa... #RavinAcademy
group-ib.com
000
Nariman Gharib @nariman.bsky.social · 22/10/2025
A comprehensive database containing complete registration records of Ravin Academy students has been obtained by me, revealing detailed personal information of individuals enrolled in the organization's training programs. blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Exclusive: Full Student Database of MOIS-Affiliated Ravin Academy Leaked
Based on the intelligence assessments from multiple government agencies, Ravin Academy functions as a MOIS-directed recruitment and training front operating und...
100
Nariman Gharib @nariman.bsky.social · 18/10/2025
000
Nariman Gharib @nariman.bsky.social · 16/10/2025
BellaCiao was developed at Tehran's Shuhada base. Moses Staff & Sahyoun24 weren't independent—all run by the same IRGC unit. MORE... blog.narimangharib.com/posts/2025%2... #APT35
blog.narimangharib.com
Part two and three of the leaked Charming Kitten files reveal operations across five continents
In my previous analysis of the Charming Kitten leak, I examined the unprecedented breach that exposed the inner workings of an Iranian state-sponsored hacking o...
021
Nariman Gharib @nariman.bsky.social · 01/10/2025
t.me/narimangharib
000
Nariman Gharib @nariman.bsky.social · 30/09/2025
Breaking News: Iranian Advanced Persistent Threat Group #APT35 Has Been Compromised, with Internal Documents Leaked Online blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Massive Leak Exposes Inner Workings of Iranian Hacking Group Charming Kitten
In what appears to be one of the most significant breaches of an Iranian state-sponsored hacking operation to date, an anonymous source has published internal d...
111
Reposted by Nariman Gharib
Joe Tidy BBC News @joetidy.bsky.social · 18/09/2025
BREAKING: Two teenagers charged over 'Scattered Spider' Transport for London cyber attack. About to appear in court for first time. I'm here for BBC so follow the story for updates: www.bbc.co.uk/news/article...
bbc.co.uk
Teenagers charged over Transport for London cyber attack
Thalha Jubair, 19, from East London, and Owen Flowers, 18, from Walsall in the West Midlands, were arrested
1105
Nariman Gharib @nariman.bsky.social · 13/09/2025
www.international.gc.ca/transparency...
international.gc.ca
Iran-linked hacker group doxes journalists and amplifies leaked information through AI chatbots
Rapid Response Mechanism Canada (RRM Canada) has detected a “hack and leak” operation by Iran-linked hacker group, “Handala Hack Team” (Handala). The operation targeted five Iran International journal...
000
Nariman Gharib @nariman.bsky.social · 10/09/2025
It's truly enjoyable to see the efforts of the Islamic Republic's cyber forces as they try to use social engineering on me.
000
Reposted by Nariman Gharib
SentinelOne @sentinelone.com · 04/09/2025
Your cyber threat intel is part of the North Korean strategy: DPRK operators are abusing CTI platforms to see if they’ve been seen—and moving faster because of it. 👀
178
Reposted by Nariman Gharib
Raphael Satter @raphae.li · 04/09/2025
Granular look here from @ajvicens.bsky.social and I on how job seekers in the crypto currency industry are being bombarded with fake job offers from North Korean hackers. Based on 19 interviews with targets and research from cyber firms @sentinelone.com and Validin www.reuters.com/world/asia-p...
reuters.com
Exclusive: How North Korean hackers are using fake job offers to steal cryptocurrency
North Korean hackers are saturating the cryptocurrency industry with credible-sounding job offers as part of their campaign to steal digital cash, according to new research, raw data, and interviews.
074
Nariman Gharib @nariman.bsky.social · 03/09/2025
There might be some kind of history in my ancestors that I’m not aware of. 😆
000
Nariman Gharib @nariman.bsky.social · 03/09/2025
🤣🤣🤣🤣🤣🤣
100
Reposted by Nariman Gharib
Cloudflare @cloudflare.social · 02/09/2025
A recent security issue announced by Salesloft has impacted many companies, including Cloudflare. Read more blog.cloudflare.com/response-to-sal…
blog.cloudflare.com
The impact of the Salesloft Drift breach on Cloudflare and our customers
An advanced threat actor, GRUB1, exploited the integration between Salesloft’s Drift chat agent and Salesforce to gain unauthorized access to Salesforce tenants of Cloudflare and many other companies.
2125
Reposted by Nariman Gharib
Catalin Cimpanu @campuscodi.risky.biz · 02/09/2025
A UK government study has found that, despite being aware that cyber insurance exists and is an option, most British companies struggle to understand insurance policy details, which is impeding a broader adoption www.gov.uk/government/p...
293
Nariman Gharib @nariman.bsky.social · 29/08/2025
Screw it, unlocking the paywall on my Charming Kitten investigation. Everyone should know how they're impersonating former Pentagon officials to target activists. Full technical details, IoCs, everything that was VIP-only is free now vip.narimangharib.com/charming-kit... #APT35
vip.narimangharib.com
Charming Kitten 2025: Strategic Target Selection and Researcher Surveillance Analysis
Overview This research examines a new Charming Kitten campaign utilizing advanced impersonation tactics, long-term monitoring of security researchers, and unique infrastructure. This analysis is base...
054
Nariman Gharib @nariman.bsky.social · 28/08/2025
The Islamic Republic is floating the idea of unblocking Telegram again blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
The Telegram Trap: Why Iran's
The Islamic Republic is floating the idea of unblocking Telegram again, and if you believe this is about digital freedom, I have a bridge in Tehran to sell you....
000
Nariman Gharib @nariman.bsky.social · 23/08/2025
In recent hours, intelligence agencies in the Islamic Republic, including the Shahid Kaveh group, have attempted to deny any cyberattacks on their ships by LabD cyber group. And as always, they said I am a member of unit 8200 of the Israeli army. 😆😆
000
Nariman Gharib @nariman.bsky.social · 22/08/2025
LabDookhtegan paralyzed 64 Iranian ships at sea last night, again... blog.narimangharib.com/posts/2025%2... #Iran #CyberAttack
blog.narimangharib.com
Inside the Lab-Dookhtegan Hack: How Iranian Ships Lost Their Voice at Sea
Lab-Dookhtegan has been systematically targeting Iranian infrastructure for months now, and when they reached out about their latest operation, I knew it would ...
100
Reposted by Nariman Gharib
Bellingcat @bellingcat.com · 14/08/2025
In May, we, alongside CBC's Visual Investigation Unit, @tjekdet.dk and @politiken.dk revealed the identity of the key administrator behind one of the largest AI porn sites. Dutch politicians across political parties are now calling for the Canadian to be extradited. www.cbc.ca/news/canada/...
cbc.ca
Dutch politicians join calls to extradite Canadian behind notorious AI porn site | CBC News
Politicians from a second European country are calling for the extradition of the Canadian man behind a notorious, pornographic website which featured deepfake images and videos of celebrities, politi...
517579
Nariman Gharib @nariman.bsky.social · 14/08/2025
Iran's defense sector offers $213,000 prize for counter-drone technology, seeking systems to detect and neutralize small UAVs through jamming, AI tracking, or physical interception. Competition highlights Tehran's push for indigenous anti-drone capabilities hxxps://archive[.]is/qCyIt
010
Nariman Gharib @nariman.bsky.social · 13/08/2025
You can watch the video here with English subtitles: blog.narimangharib.com/posts/2025%2...
blog.narimangharib.com
Handala Hacker Exposed: Iran International Identifies Intelligence Ministry Operative Behind Cyber Attack
Tonight, Iran International TV revealed the identity of one of the key figures behind the Handala hacking group that claimed responsibility for attacking the ne...
011
Nariman Gharib @nariman.bsky.social · 13/08/2025
Tonight, Iran International TV exposed the identity of a Handala hacking group admin—part of the Banished Kitten cyber unit I've previously reported on—and unmasked his handler in Iran's Ministry of Intelligence. - Morteza Aftabi-Far - Ali Bermoudeh
1143
Nariman Gharib @nariman.bsky.social · 09/08/2025
011
Nariman Gharib @nariman.bsky.social · 09/08/2025
This is the first time I’ve published this kind of information behind a paywall, and interestingly, the CK team hasn’t picked it up yet. lol #APT35
000