Iranopasmigirim - Unmasking an ever-evolving GitHub-Hosted Espionage Campaign Against Iranian Dissidents

No ratings

Presented at BSides Tallinn 2026 by

What began as routine triage of low-detection malware from MalwareBazaar quickly revealed a full-fledged campaign targeting dissidents, using Custom-built tooling with no meaningful overlap with known malware families, pointing to a dedicated, well-resourced developer rather than a repurposed off-the-shelf toolkit. This talk walks through the investigation from that first sample to a fuller picture of the Threat Actor, which has focused on espionage-motivated targeting connected to Iran. We detail the malware's architecture and capabilities, and show how pivoting on code artefacts, unique behavioural fingerprints, and network indicators allowed us to cluster additional, previously unattributed samples under the same actor. This talk shows the ever-changing TTPs and Malware being used, from C++-based malware, over Nim and Go, to finally Rust. Attendees will leave with a concrete case study in threat actor discovery starting from minimal initial evidence, practical pivoting techniques for connecting sparse indicators into a coherent cluster, and a set of detection opportunities and indicators for identifying this activity. This talk is aimed at a broad security audience and requires no prior familiarity with the actor, offering both a compelling investigative narrative and actionable takeaways for threat hunters, analysts, and defenders alike.