← Dynamic Research
Dynamic Research

Iran's State AI Playbook: Sovereignty on a Sanctions Budget

How Tehran turned open-source LLMs, Chinese hardware, and hijacked Western cloud accounts into a functioning wartime AI program — and what it means for anyone tracking Iranian threat activity.

Why this matters

Iran cannot buy an H100. Export controls have kept the country off the leading edge of AI hardware for years, and a fragile power grid makes even mid-sized data centers a gamble. None of that has stopped Tehran from running a functioning, state-directed AI program — it has just changed the shape of it. Instead of building frontier models, Iran downloads them. Instead of building data centers, it borrows Microsoft's. Instead of waiting on domestic chip fabrication, it leans on a 25-year strategic partnership with Beijing for the hardware backbone. The result is a dual-track system: a starved commercial AI sector next to a well-resourced state apparatus purpose-built for surveillance, judicial automation, and offensive cyber operations.

That second track is the one worth tracking closely, because pieces of it show up directly in the intelligence FlagThis already indexes — the same APT groups behind Iran's AI-assisted phishing and cloud-abuse campaigns are ones we track on our Threat Actor pages, and the compute-scarcity workarounds described below (quantized open-weight models, hijacked Azure tenants) explain why those groups' tradecraft has visibly improved.

Iran's own defense officials put the shift in blunt terms: AI-assisted reconnaissance has cut the average "time-to-exploit" for a known vulnerability from months to about five days.

A directive from the top

The policy origin is a single speech. In November 2021, Supreme Leader Ali Khamenei named artificial intelligence an "important and futuristic issue" and ordered Iran into the world's top ten AI-producing nations — explicitly framed as resistance to Western technological dominance, not as an economic development program. Three years later, in August 2024, he sharpened the urgency: he warned that the West could eventually stand up an IAEA-style regulatory body for AI, one that would restrict advanced-model access to states it judges hostile. The read inside Iran's leadership was that a window exists now to build irreversible AI capability before any such "algorithmic sanctions regime" closes it.

That fear of a closing window, more than any commercial ambition, explains the pace of what followed. President Ebrahim Raisi's government ratified a National Artificial Intelligence Document committing roughly $8 billion in state investment and targeting AI for 12% of GDP — a program his successor, Masoud Pezeshkian, kept intact after Raisi's death in 2024.

One organization to run it all

Iran's AI policy used to be scattered across the Ministry of Communications, the Ministry of Industry, the Supreme Council of the Cultural Revolution, and assorted military branches — exactly the kind of bureaucratic fragmentation that slows a state down. Pezeshkian's government fixed that in July 2024 by standing up the National Artificial Intelligence Organization, an independent body reporting directly to the President's office. Parliament made the arrangement permanent in October 2025.

The leadership picks tell you what the organization is really for. Chairman is First Vice President Mohammad Reza Aref, a Stanford-trained electrical engineer; the operational lead is Hossein Afshin, a Sharif University of Technology professor and VP for Science, Technology, and Knowledge-based Economy. Centralizing AI under the presidency — rather than, say, a telecom regulator — is itself a signal: it puts model development, judicial automation, and security-service surveillance tooling under one command structure instead of three uncoordinated ones.

The commercial side has been left to starve by comparison. Iran's Parliament Research Center estimates AI will touch roughly 20% of existing jobs, but the state has put less than $50 million total into private-sector AI innovation — a rounding error next to the security and judicial buildout described below.

The domestic LLM stack: sovereignty on consumer hardware

Iran's answer to not having frontier-scale compute was to stop trying to compete on that axis entirely. Iranian labs and quasi-private tech firms take open-weight models published by Meta and Mistral AI and fine-tune them on Persian-language data — skipping the billions of dollars of pretraining cost that produced the base model in the first place. Persian, along with related languages like Kurdish, Balochi, and Pashto, was a genuinely low-resource language family for NLP research until fairly recently; that gap is closing fast, helped along by venues like the SilkRoadNLP workshop at EACL 2026.

Three efforts anchor the current Persian-LLM landscape:

Model Developer Base Size Notes
Dorna-Llama3 PartAI (Part Software Group) Meta Llama 3 8B Marketed as the strongest Persian instruction-following model under 10B params; shipped in 4-bit/8-bit GGUF quantizations via Ollama and Hugging Face for consumer GPUs.
Maral-7B (Alpha 1) MaralGPT Mistral 7B 7B Fine-tuned on a translated Persian Alpaca dataset; roughly GPT-3.5-level Persian fluency, with acknowledged hallucination issues.
Fibonacci Series fibonacciai Various 0.2B–15B A family of narrower models (Iran-v1, fibonacci-2-9b, RealRobot-Chatbot) aimed at e-commerce and QA rather than general chat.

The pattern across all three is the same: take a Western open-weight release, apply LoRA fine-tuning against a translated instruction dataset (Stanford Alpaca shows up repeatedly), and ship a quantized GGUF build that runs on a single consumer GPU. It's worth naming the second-order effect plainly — every time a Western lab open-weights a capable base model, it hands a sanctioned state a multi-million-dollar head start it would otherwise not have.

Borrowed compute: sanctions evasion, three ways

Getting a model onto a laptop is one problem. Running large-scale reconnaissance, judicial-record processing, or drone-targeting inference at national scale is a different, much bigger compute problem — and this is where Iran's actual hardware ceiling shows. The 2025 IDCA Global AI Report flags Iran's power grid, not chip access, as the binding constraint against better-resourced regional rivals like Saudi Arabia and the UAE. The country's flagship supercomputer, Simorgh at Amirkabir University of Technology, tops out in the single-digit petaflops range, and a domestic chip-fabrication effort ("Sahand") remains years from relevance under current EUV lithography export controls.

Three workarounds fill the gap:

Quantization. Shrinking an 8B-parameter model from ~16GB down to under 5GB via 4-bit/8-bit GGUF formats turns a data-center problem into a gaming-PC problem. This is the same technique behind the Dorna-Llama3/Maral-7B releases above, and it's the main reason Iran can field usable LLMs at all without EUV-grade silicon.

Parasitic cloud abuse. Rather than build data centers Iran can't power, its state-sponsored cyber units simply rent Western cloud compute using stolen credentials. Microsoft and Palo Alto Networks have both documented Iranian APT groups running the open-source ROADtools framework against Microsoft Entra ID environments — enumerating victim directories, forging authentication tokens, registering rogue devices — then standing up fraudulent Azure subscriptions (frequently funded through credentials harvested via password-spraying campaigns against universities) to host command-and-control infrastructure and run data-intensive reconnaissance for free.

The North Korea playbook, potentially. Analysts also flag the possibility Iran adopts North Korea's "remote IT worker" fraud model — infiltrating Western companies as contractors to quietly use employer-provided compute and route hard currency home. There's no confirmed large-scale Iranian version of this yet, but it's a natural next step given how well the cloud-abuse playbook has already worked.

The China backstop

When neither quantization nor cloud theft is enough, Iran leans on its 2021 25-year, $300 billion Comprehensive Strategic Partnership with Beijing — hydrocarbons in exchange for infrastructure, military coordination, and technology transfer. On the AI side, four transfers matter most:

  • Surveillance optics: Tiandy Technologies, the Tianjin firm behind much of Xinjiang's Uyghur surveillance apparatus, supplies the IRGC and Iranian police with AI-driven facial recognition, thermal imaging, and emotion-detection cameras.
  • Deep packet inspection: Huawei and ZTE built the DPI backbone of Iran's "National Information Network" — the country's censored domestic intranet, which lets the state monitor landline, mobile, and internet traffic and "coup-proof" itself against unrest.
  • Navigation: Iran's military has migrated off US GPS onto China's BeiDou-3 system for encrypted, jam-resistant positioning with a built-in short-message channel for when local telecom is cut during conflict.
  • SIGINT and radar: China's satellite constellation feeds Iran signals intelligence on US/Israeli naval movement in the Persian Gulf, and Chinese UHF-band radar (YLC-8B) is tuned specifically to blunt US stealth-coating advantages.

The relationship is transactional in both directions, not just Chinese generosity — Iran functions as a live-fire test range for Chinese hardware against real US/Israeli electronic warfare, data Beijing feeds back into its own systems ahead of a possible Taiwan contingency. Iranian officials have reportedly been disappointed at how little of that partnership translates into actual military backing when conflict escalates; Beijing has stuck to diplomatic statements rather than intervention, which tells you the ceiling on this alliance.

AI on the offense: Iran's cyber units

This is the part of Iran's AI program most directly relevant to FlagThis's own tracking. IRGC-linked APT groups have visibly shifted from manually-crafted phishing and scanning toward AI-assisted tradecraft — the "average time-to-exploit" figure cited at the top of this post is the clearest single indicator of that shift. Three groups carry most of the public reporting on this: Peach Sandstorm's AI-assisted reconnaissance against critical infrastructure, Mint Sandstorm's LLM-drafted spear-phishing, and CyberAv3ngers' generative-AI-accelerated targeting of industrial control systems.

Threat actor Also tracked as Primary targets AI-assisted tradecraft
Peach Sandstorm Refined Kitten, Elfin, APT33 US/UAE critical infrastructure, space, oil & gas, defense AI-assisted vulnerability scanning and password-protocol bypass; deployed the multi-stage "Tickler" backdoor (Apr–Jul 2024) via fraudulent Azure infrastructure to map networks and exfiltrate data.
Mint Sandstorm Charming Kitten / TA453, APT42 (naming varies by vendor — Microsoft, Mandiant, and CrowdStrike don't fully agree on where the lines between these groups sit) High-profile individuals, academics, political campaigns, Israeli targets Uses LLMs to draft fluent, culturally-calibrated spear-phishing lures in multiple languages and to enumerate Entra ID cloud environments via ROADtools.
CyberAv3ngers Soldiers of Solomon, Shahid Kaveh Group, Hydro Kitten Industrial control systems, European & Israeli infrastructure Generative AI to rapidly ingest ICS source code, map control-system architecture, and accelerate vulnerability research ahead of an intrusion.

Historically, Iranian phishing was often identifiable by its tells — awkward grammar, cultural misreads, stiff phrasing. LLM-assisted drafting has quietly removed that signal. Mint Sandstorm now scrapes public profiles (LinkedIn in particular) to tailor lures to a target's actual professional context, in the target's own language, without the grammatical fingerprints defenders used to key on.

The Storm-2035 playbook

Iran's AI use isn't limited to intrusion — it also runs hyperscale influence operations. OpenAI and partner researchers disrupted a network dubbed Storm-2035 in August 2024, which used ChatGPT to run a largely-automated disinformation pipeline: long-form political articles, social posts, and polarizing commentary published across a stable of fake outlets (EvenPolitics, Nio Thinker, Savannah Time, Teorator, Westland Sun) aimed at both progressive and conservative US audiences around the 2024 election. The economics here matter more than the specific takedown — an LLM turns "maintain a troll farm of human writers and translators" into "scrape trending stories and instruct a model to rewrite them with a slant," which is a cost collapse of roughly two orders of magnitude for running an influence campaign at scale.

The paper trail: malware, CVEs, and infrastructure

Everything above describes behavior. This section is the receipts — the specific malware families, exploited CVEs, MITRE ATT&CK identifiers, and named individuals public reporting has actually attributed to these three actors, so the claims above aren't just narrative. Every CVE here links to its FlagThis tracking page.

Peach Sandstorm / APT33 (MITRE G0064)

Peach Sandstorm's initial-access playbook increasingly leans on exploiting n-day vulnerabilities with public proof-of-concept code rather than custom zero-days. Microsoft has attributed exploitation of CVE-2022-47966 (a Zoho ManageEngine remote-code-execution flaw) and CVE-2022-26134 (an Atlassian Confluence RCE) directly to the group for initial access, on top of its long-running password-spray campaigns.

Once inside, the group's tooling spans a genuine mix of custom code and repurposed open-source red-team frameworks:

Tool Type What it's for
Tickler Custom multi-stage backdoor The Apr–Jul 2024 campaign; Microsoft's writeup names the dropped files Network Security.zip (a decoy archive bundled with real PDFs) and sold.dll (the actual Trojan dropper).
FalseFont Custom backdoor Documented separately targeting the defense industrial base; see Nextron Systems' analysis.
ROADtools / AzureHound Open-source Entra ID recon (abused) Legitimate, publicly maintained red-team tooling on GitHub, reused post-compromise to map victim tenants.
Quasar RAT Open-source .NET RAT (abused) Freely available on GitHub; CISA has separately flagged Quasar as a tool of choice across many APT groups, not unique to Iran.
PoshC2, Pupy Open-source C2/RAT frameworks (abused) Commodity red-team tooling per Malpedia's APT33 profile, alongside leaked/commercial RATs (NanoCore, DarkComet, NetWire, Remcos) the group has used opportunistically since 2013.

Its cloud infrastructure follows the pattern described above: fraudulent Azure-for-Students subscriptions, created with compromised university credentials, hosting the C2 for Tickler and other campaigns.

The Charming Kitten cluster (MITRE G0059 / G1044)

The naming mess here is real and worth stating plainly rather than glossing over: Microsoft's "Mint Sandstorm," Mandiant's "APT42," and Proofpoint's "TA453" overlap substantially but aren't a guaranteed 1:1 mapping, and MITRE tracks them as two separate group entries — G0059 for the older TA453/Charming Kitten cluster, G1044 specifically for APT42. Tooling attributed across the cluster includes PINEFLOWER (an Android implant), TAMECAT (a PowerShell-based backdoor), and NICECURL (a VBScript implant), all cataloged in MITRE's G1044 entry. The cluster shares Peach Sandstorm's habit of running ROADtools against Entra ID once inside a victim's cloud tenant.

CyberAv3ngers (MITRE G1027)

This is the most heavily attributed of the three. CyberAv3ngers — also tracked as Soldiers of Solomon, the Shahid Kaveh Group, Hydro Kitten, Storm-0784, Bauxite, Mr. Soul, and UNC5691 — is a front for the IRGC's Cyber-Electronic Command (IRGC-CEC). In an unusually direct move, the U.S. Rewards for Justice program named six individuals it assesses are behind the group's US-facing operations, offering a $10 million reward for information leading to their identification: Hamid Homayunfal, Hamid Reza Lashgarian (head of the IRGC-CEC and, separately, an IRGC-Qods Force commander), Mahdi Lashgarian, Milad Mansuri, Mohammad Amin Saberian, and Mohammad Bagher Shirinkar.

The group's exploitation chain is unusually well-documented because it's been running against US critical infrastructure continuously since 2023:

  • CVE-2023-6448 — Unitronics Vision/Samba PLCs and HMIs ship with a default administrative password (1111). This is the root cause of the November 2023 breach of the Municipal Water Authority of Aliquippa, Pennsylvania, and at least 75 other Unitronics devices compromised across the US, UK, Israel, and Ireland through January 2024, per CISA advisory AA23-335A. Compromised HMIs displayed a defacement message: "You have been hacked, down with Israel."
  • CVE-2021-22681 — an unpatched authentication bypass in Rockwell Automation Logix controllers, added to CISA's Known Exploited Vulnerabilities catalog in March 2026 after confirmed CyberAv3ngers exploitation.
  • IOCONTROL — custom malware targeting IoT/OT gear from Baicells, D-Link, Hikvision, and Red Lion, per Rewards for Justice.

CISA's updated advisory AA26-097A (April, expanded July 2026) shows the campaign has since widened well past Unitronics — to Schneider Electric (BMX P34 / Modicon M340) and Siemens (S7-1200 series) controllers — using the vendors' own legitimate engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) over exposed remote access, plus Dropbear SSH, rather than novel exploit code. The group's public-facing presence is its Telegram channel, @CyberAveng3rs, launched in September 2023, which it uses to publish target lists and claim credit — most recently for an August 2026 coordinated attack on Minnesota municipal water-utility SCADA/ICS systems, which the group described as "only to warn."

Outside the surface web

None of the three actors tracked in this post has a confirmed, stable Tor/.onion presence in current public reporting — their claims channels are Telegram, not dark-web forums. The wider Iranian state-linked ecosystem does run hack-and-leak infrastructure reachable over Tor, though: CISA advisory AA24-241A covers Iran-based actors enabling ransomware operations with dedicated leak sites, and groups like Pay2Key (tracked as HomeLand Justice / Nemesis Kitten) and the hacktivist-branded Handala Hack persona both maintain Tor hidden services alongside Telegram and BreachForums accounts. We're deliberately not publishing specific onion addresses here — they rotate, and a stale one printed in a research post is worse than useless — but they're discoverable through the CISA advisory and the dark-web threat-intel trackers cited in Sources below if you need them for defensive blocklisting.

AI on the inside: judiciary and street-level policing

The most mature, least ambiguous application of Iranian state AI is domestic, not offensive.

Tenad, the judiciary's AI system, is trained on more than 110 million historical rulings and legal records, and is used to standardize sentencing, locate a citizen's financial assets in minutes, and auto-issue legal certificates. The structural problem is not subtle: a model trained on rulings from a judiciary widely documented for arbitrary detention and forced confessions will learn — and then systematize — that judiciary's biases. Iran's Supreme Court reportedly uses "alignment with the model's recommendation" as one signal of judicial performance, which creates a feedback loop actively discouraging judges from deviating from the AI's historically-harsh baseline.

Nazer, a facial-recognition enforcement app, is the direct policy response to the 2022 "Woman, Life, Freedom" protests: rather than risk more street confrontations over hijab enforcement, the state moved enforcement into automated, remote detection. Built on Chinese CCTV and drone hardware (Tiandy again) and interaction-tracking software in the style of FindFace, Nazer flags non-compliant individuals for automatic fines, vehicle impoundment, or arrest. The UN's Independent International Fact-Finding Mission on Iran has specifically called out the "chilling" effect of always-on automated enforcement with no meaningful appeal path.

The military dimension

IRGC commanders have been explicit that centralized AI governance is meant to speed up military decision cycles and improve targeting. Iran is watching the same AI-assisted targeting systems everyone else is — Israel's "Lavender" and "Gospel," the US military's Project Maven — and drawing the obvious conclusion that modern targeting speed is now an algorithmic problem. With Russian combat-data sharing from Ukraine and Chinese SIGINT from the Gulf, Iran is working to improve autonomous drone targeting and the guidance systems on assets like the CM-302 supersonic missile.

There's also a colder read from Iranian analysts on the defensive side: LLM sycophancy — models tending to confirm a user's existing assumptions rather than challenge them — is being studied as an exploitable weakness in how adversaries use AI for military planning, not just a curiosity.

Timeline

Date Event Why it mattered
Mar 2021 Sino-Iranian 25-year Strategic Partnership signed Locked in the Chinese hardware/surveillance pipeline described above.
Nov 2021 Khamenei's top-10 AI directive Reframed AI as national-security policy, not commercial development.
Late 2022–2023 "Woman, Life, Freedom" protests Triggered the pivot to Nazer-style automated enforcement.
Dec 2023 National AI Steering Committee established First formal centralization attempt under Raisi.
Apr–Jul 2024 Peach Sandstorm deploys "Tickler" First widely-documented use of fraudulent Azure infra for a live backdoor campaign.
Jun 2024 National Artificial Intelligence Document approved Formalized the $8B/12%-of-GDP investment target and the Tenad rollout.
Jul 2024 National AI Organization launched Centralized command under the Presidency.
Aug 2024 Storm-2035 disrupted by OpenAI First confirmed large-scale Iranian use of ChatGPT for influence-op content generation.
Oct 2025 National AI Organization codified by Parliament Made the centralized structure permanent.

What we're watching

Three things are worth monitoring going forward, and we'll fold updates into this post as they develop: whether Peach Sandstorm/Mint Sandstorm tradecraft keeps converging (shared infrastructure, shared AI tooling) in ways that argue for tighter attribution; whether CyberAv3ngers' PLC campaign keeps widening past Unitronics, Rockwell, Schneider Electric, and Siemens into other vendors; and whether the "algorithmic sanctions" fear that's driving Tehran's urgency actually materializes as real export-control or model-access restrictions.

The second one already moved once since this post's first draft: CISA's advisory update confirmed the Schneider Electric/Siemens expansion, and CyberAv3ngers claimed a fresh attack on Minnesota water-utility SCADA systems days before this revision — see "The paper trail" above for both.

Sources

Revision History
This page is a living document — every update is logged here.
2026-08-16
Initial publication — adapted from a source intelligence report covering Iran's state AI/LLM strategy, domestic Persian-LLM ecosystem, sanctions-evasion tactics, Sino-Iranian tech transfer, offensive cyber use, domestic repression tooling, and the military dimension.
🤖 claude-skill initial publication
2026-08-16
Redesigned the masthead (fixed a global CSS `header` selector collision that was squeezing the title/dek/byline into a broken layout) and added a Key Takeaways abstract at the top of the page.
🤖 claude-skill presentation feedback
2026-08-16
Added "The paper trail" section: concrete malware families (Tickler, FalseFont, IOCONTROL, PINEFLOWER/TAMECAT/NICECURL), exploited CVEs (CVE-2022-47966, CVE-2022-26134, CVE-2023-6448, CVE-2021-22681, all linked to FlagThis's own CVE pages), MITRE ATT&CK group IDs (G0064, G0059, G1044, G1027), the six individuals the U.S. government has sanctioned for CyberAv3ngers, and an honest accounting of what dark-web/Tor presence is and isn't confirmed for these three actors. Also added inline hyperlinks throughout the rest of the post (SilkRoadNLP, model repos, ROADtools, Storm-2035, Tenad, Nazer) and updated "What we're watching" with developments confirmed since first publication.
🤖 claude-skill deeper research pass — concrete indicators requested

LINK COPIED TO CLIPBOARD