Operating under the ceiling¶
Iran and the line that is not crossed
Iranian cyber operations tend to be narrated in the key of menace. The wiper that erases tens of thousands of machines, the hack-and-leak that dumps a company’s secrets, the intimidating email signed by a false name: the register is theatrical, and the actor is read as ideological, vengeful, a little reckless. The theatre is not incidental, as it turns out. It is most of the point. But reading it as temperament misses the discipline underneath.
What is telling is not what the operations express but what they are careful not to do. The recurring feature of Iranian activity is a threshold it declines to cross: enough destruction to be felt, enough exposure to be denied, and almost never enough to justify the kind of response the state could not absorb. The signature is calibration: how much, and no more.
A doctrine of the affordable¶
A state under sustained economic pressure, without the resources for a symmetrical contest against better-armed adversaries, finds in cyber operations a domain where the costs are low, the deniability is high, and the effects can be dialled. The capability is assembled to match: rather than a single stable apparatus, Iran runs its operations through the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security, tasking a rotating set of university-linked institutes and private contractor firms, each a front that can be renamed or disowned. The instrument suits the doctrine: cheap, plausibly separable from the state, and tunable in intensity.
The coupling: destruction with a governor on it¶
The clearest expression is the wiper, a tool built to destroy rather than steal or extort. In 2012 the Shamoon malware erased the master boot records of around thirty thousand computers at Saudi Aramco, reportedly in retaliation for an earlier wiper strike on Iran’s own oil ministry. Later variants followed the same pattern against regional energy and industrial targets: Shamoon 2 and 3, then ZeroCleare and Dustman, the last of these against a Bahraini oil company. The wiper is the calibrated weapon par excellence. It causes expensive, visible damage, and it stops well short of the physical casualties that would move a conflict into a register Iran has no interest in entering. Analysts describe the class precisely this way: a means to retaliate and signal disdain below the level of armed conflict, while keeping deniability and holding down the risk of escalation.
The same governor is visible when the target is a person rather than a plant. In 2014 a data-wiping attack hit the Las Vegas Sands casino company, whose owner Sheldon Adelson had publicly urged a nuclear strike on Iran; the then US Director of National Intelligence later attributed the attack to Iran. The response was pointed at a specific provocation and sized to embarrass rather than to cripple.
Where the effect wanted is on belief rather than hardware, the tool changes but the calibration holds. In the run-up to the 2020 US election, operators working through the contractor Emennet Pasargad obtained voter data and sent threatening emails purporting to come from the Proud Boys, a domestic extremist group, telling recipients to change their party registration. Two contractors were later charged and the firm sanctioned. The operation touched an election without altering a vote, an information effect pitched to unsettle rather than to seize. At the lowest rung, the symbolic touch on physical infrastructure: a group calling itself CyberAv3ngers, tied to the IRGC, compromised Israeli-made control devices at water utilities in the United States and Israel, leaving many simply displaying the message “You have been hacked, down with Israel.” Access to operational technology, used to post a slogan rather than to open a valve. The capability was demonstrated; the line was not crossed.
The churn is a tell¶
If the wiper is the calibrated weapon, the contractor front is the calibrated identity. The firm behind the 2020 election operation illustrates it: it began as Eeleyanet Gostar, was charged under the name Emennet Pasargad, and by mid-2024 was operating as Aria Sepehr Ayandehsazan, a fresh corporate shell for the same activity. Alongside the corporate renaming runs a churn of invented hacktivist personas: the same group has posted stolen material as a pro-Palestinian outfit called Hackers of Savior and as a criminal persona called Deus, and the FBI has noted its habit of making exaggerated or fictitious claims of access to inflate the apparent damage. The renaming is not housekeeping. It is exposure management, a way of keeping each operation deniable and each escalation reversible, and it is itself a print of a system that expects to be caught and plans for it.
Where the tidy version breaks¶
Two complications bear on the word calibration.
The first is that the ceiling is not fixed, and appears to be drifting upward. In July 2022 Iran conducted a destructive wiper-and-leak attack on Albania, a NATO member, over its hosting of an exiled Iranian opposition group, and Tirana severed diplomatic relations in response. Striking a member of the alliance sits considerably higher than the early denial-of-service raids on banks, and the direct exchanges of the 2025 Israel-Iran confrontation pushed higher still. Whether this reflects a raised tolerance for risk, a misreading of where the line now sits, or simply a widening of capability is not something the outside record settles.
The second is that calibration may over-ascribe coherence. To call the pattern calibrated implies a single actor consciously holding a line, and the evidence is also consistent with less tidy explanations: opportunistic target selection, capability limits that impose their own ceiling, and the friction of multiple IRGC and MOIS contractors pursuing their own objectives without central choreography. The FBI’s own assessment describes at least one of these groups as opportunistic in its choice of victims rather than working a fixed target list. The restraint is observable in the outcomes. The intention behind it is inferred, and the inference is the weakest link.
What stays open¶
Iranian internal decision-making is largely opaque, and much of what can be said rests on behaviour observed from outside rather than on leaked paperwork or indicted insiders describing a chain of command. The threshold is what can be observed; the intention behind it stays an open branch, not a strategic mind the sources cannot reach.
Iran’s case bends toward the manufacture of truth rather than the vocabulary of attribution. More than any of the other three, Iranian operations aim at belief: the false-flag persona, the leak staged for reputational damage, the inflated claim of access, the intimidating email wearing a domestic extremist’s name. The object is an impression in a target audience, and the technical intrusion is often just the delivery mechanism for it. That places these operations closer to information warfare than to theft or sabotage, and it is here that the question of who manufactures a narrative, and why it is believed, comes closest.
What survives is a single reframing. The destruction, the leaks and the slogans are easy to read as the expression of a temperament, ideological and vengeful. They read better as the output of a constraint. A state that cannot afford open confrontation builds a capability that can be felt and denied in the same motion, and calibrates each use to stay under a ceiling it cannot afford to breach. The behaviour is a function of the ceiling, not of the temper it is so often mistaken for.