Kashef: The IRGC’s Integrated System for Data Collection and Citizen Surveillance
A leaked video offers a rare look inside Kashef, a system used by the IRGC’s Ministry of Intelligence to turn identity and phone records, device IDs, location and travel data—even visits to diplomatic sites—into searchable profiles of individuals and their networks.


In the fall of 2025, a large collection of documents and operational artifacts linked to an Iranian advanced persistent threat (APT) actor was released, prompting widespread scrutiny across the cybersecurity community and the media. Published under the title “CharmingKitten” by a group or account using the name KittenBusters, the archive includes internal files, daily reports, source code, server logs, and screenshots of internal conversations. Taken together, the material exposes the structure, methods, and operational scope of a cyber unit affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO): Department 40, also known as Unit 1500 and, more widely, Charming Kitten.
Related Articles
Among the leaked materials is a video of version 3.0.1 of “Kashef,” a system attributed to IRGC Intelligence and dated Khordad 1401 (May–June 2022). The footage shows a web-based application used to search and aggregate citizens’ identity and communications data. By entering only part of a phone number, an operator can retrieve possible subscriber names, birth-certificate numbers, dates of birth, fathers’ names, addresses, postal codes, and thousands of call and SMS records. The operator can then render the individual’s communications network as a graph.
Kashef is formally described as the “System for Detecting and Identifying Individuals.” Its significance lies in its ability to connect fragmented information collected from different sources and transform a citizen’s identity, movements, and network of relationships into a single intelligence file.
Kashef System; Data Fusion, Relationship Mapping, and Operational Surveillance
Beyond individual surveillance operations, one of the most consequential dimensions of the Islamic Republic’s digital control strategy is data aggregation. Rather than relying solely on isolated interceptions or targeted espionage, the state increasingly prioritizes the systematic collection, correlation, and analysis of user data across platforms, services, and identifiers. In this model, surveillance power derives not from single data points, but from the ability to fuse disparate datasets into coherent behavioral profiles.
Disclosures related to the Charming Kitten operations illustrate this logic in practice. The group’s infrastructure was not limited to malware delivery or account compromise; it functioned as a data pipeline. Collected information including credentials, session tokens, metadata, contact networks, and content archives was stored, indexed, and cross-referenced over time. This enabled the construction of identity-to-behavior mappings that extend beyond individual incidents and support long-term monitoring objectives.
This aggregation-centric approach closely mirrors state-level practices observed across domestic platforms. Backend access to Iranian services such as messaging apps, marketplaces, navigation tools, and payment systems allows authorities to correlate behavioral signals across domains: communication patterns, location data, transaction histories, and social relationships. When combined, these datasets produce a level of visibility far exceeding that of conventional lawful interception.
Crucially, data aggregation collapses the distinction between targeted and mass surveillance. Even when access originates from discrete sources, the resulting datasets scale horizontally, capturing populations rather than individuals. This architecture transforms ordinary digital exhaust into an intelligence asset, enabling predictive analysis, social graph construction, and retrospective investigation without continuous active interception.
In this context, Charming Kitten should not be understood merely as a cyber-espionage actor, but as an operational prototype for data-driven surveillance. Its methods demonstrate how decentralized collection can feed centralized analysis, reinforcing a broader state strategy that treats user data as a strategic resource. The convergence of state-backed platforms, privileged backend access, and external data harvesting points toward an increasingly unified surveillance architecture, where aggregation itself becomes the primary mechanism of control.
One of the most consequential revelations about the Islamic Republic’s covert surveillance ecosystem is the exposure of a platform known as Kashef, a centralized intelligence system designed to aggregate, correlate, and operationalize vast volumes of personal data. Unlike the surveillance vectors discussed earlier in this section, Kashef does not rely on malware delivery, platform cloning, or direct user interaction. Instead, it functions as a back-end intelligence fusion engine that transforms disparate datasets into actionable relationship and behavioral maps.
RaazNet Investigates Kashef: How the System Identifies and Tracks Individuals
Investigations revealed that Kashef enables operators to input the identity of a target individual and retrieve a structured network of associations, including family members, frequent contacts, travel history, and geospatial presence. The system correlates metadata from multiple sources, such as mobile phone records, location data, airline manifests, and leaked or exfiltrated databases obtained through cyber operations. By combining these inputs, Kashef generates a dynamic graph of relationships that can be queried, expanded, and filtered based on investigative or operational needs.

According to available reporting, Kashef is used by security and intelligence units to identify social networks, trace indirect connections, and surface hidden links between individuals and locations. Rather than surveilling communications in real time, the platform reconstructs patterns of life after the fact, allowing authorities to infer trust relationships, logistical coordination, and movement patterns. This capability makes Kashef particularly valuable for intelligence-led policing, counter-dissent operations, and transnational targeting.

Crucially, Kashef appears to function as a downstream consumer of data collected through other surveillance mechanisms described in this report. Information harvested via spyware campaigns, administrative access to domestic platforms, lawful intercept systems, and cyber intrusions can be ingested into Kashef, where it is normalized and cross-referenced. In this sense, Kashef represents the convergence point of the Islamic Republic’s surveillance stack: a system where interception, data access, and behavioral monitoring coalesce into a single analytical framework.

The architecture and use of Kashef illustrate a shift from fragmented surveillance toward integrated intelligence production. Rather than relying on isolated datasets or single-purpose tools, the Islamic Republic has invested in systems that enable long-term profiling and predictive inference. This model blurs the boundary between domestic surveillance and intelligence operations, enabling authorities to repurpose civilian data for security objectives without judicial transparency or meaningful oversight.
Kashef thus exemplifies the maturation of surveillance governance in the Islamic Republic: a move from monitoring communications to mapping societies. By transforming personal data into relational intelligence, the system operationalizes digital traces as instruments of control, extending the reach of state surveillance beyond individual platforms and into the structure of social life itself.
1) Data Ingestion
In practice, Kashef is a data-fusion platform that identifies connections among seemingly unrelated pieces of information. The system does not necessarily generate the data itself. Each source holds only one fragment of an individual’s life: mobile operators, identity-registration systems, records of international travel, and data obtained through cyberattacks. Viewed separately, these fragments may appear to be routine administrative records. Kashef combines them to construct, from a name or phone number, a picture of the person’s identity, communications, movements, and social network.
The leaked interface clearly separates two stages: “Search” and “Merge.” The operator first selects the sources to be queried, after which Kashef links the results. A phone number can therefore lead to identity details, call records, a device identifier, an approximate location, and people associated with the subscriber. The assignment of a separate identifier to every search also suggests that queries are retained as cases that can be logged, retrieved, and managed within the system.
2) Which Databases Can Kashef Access?
On the right-hand side of the interface, data sources are grouped under several intelligence directorates: Directorate 1530, labeled “Persian Gulf”; Directorate 1540, associated with Israel; Directorate 1550, labeled “United States”; and Directorate 1560, or the “Foreign Nationals Directorate.”
The expanded list under the Foreign Nationals Directorate is more revealing than the directorate’s name. It includes sources labeled:
- Foreign travel by Iranian citizens
- Owners of lines in the “Special Print” dataset and “Special Print” records
- Dual nationals
- Iranian holders of a second nationality, based on Ministry of Interior data
- Students studying abroad
- Movements of people and vehicles to diplomatic premises
- Employees of Iranian embassies
- Companies linked to foreign entities
- International journalists’ assignments
- Lists of international journalists
- Social media
The system’s architecture indicates that these groups and behaviors were defined from the outset as searchable categories. In other words, dual nationality, studying abroad, ties to a foreign company, journalism, or even visiting diplomatic premises are treated in Kashef’s design not merely as administrative attributes, but as intelligence indicators.
The system also displays the technical fields LAC, cell, and sector. These refer to the location area, cell site, and antenna sector within a mobile network and can indicate a handset’s approximate location when a communication occurred. They are not equivalent to precise GPS coordinates. When analyzed across multiple records, however, they carry significant intelligence value for reconstructing a phone’s general area of presence and movement.
3) Data Retained for Nearly a Decade
One of the most significant details underexamined in the initial reporting is the age of the data displayed. The version of Kashef shown in the video dates to 2022, but some of the identity and communications records returned in the results date to the Iranian calendar years 1391 and 1392, corresponding roughly to 2012–2014.
This indicates that, at least in the example shown, the system had access to records approaching a decade in age. Kashef is therefore not only a tool for finding a person’s current location or connections; it can also be used to reconstruct relationships historically. A phone number abandoned years ago, a long-forgotten call, or an address where the person no longer lives may remain part of a searchable intelligence file.
4) Turning a Contact into a Relationship with One Click
The “Relationship Graph” page places a phone number and the name attributed to its subscriber at the center of the graph. Around them, the system categorizes incoming calls, outgoing calls, received text messages, and sent text messages.
This is the point at which metadata becomes an intelligence file. An operator does not need to know what was said during a call. Knowing who communicated with whom, on what date, how often, and from which approximate network location can be sufficient to map a person’s social and professional networks.
The consequences extend beyond the person directly targeted. Anyone who appears in that individual’s communications records can become a new node in the graph, after which the new person’s own connections can be examined. Surveillance can therefore expand from an initial target to friends, colleagues, family members, journalistic sources, or even incidental contacts.
5) How Does New Data Enter Kashef?
An add-file icon appears beside each data source. The operator can select a file or drag and drop it into the system. Kashef checks the file name against the selected source, confirms successful ingestion, and displays a duplicate warning if the same dataset has already been uploaded.
Search results can also be exported to a CSV file with a single click. Kashef is therefore not a closed, static database; its architecture is designed for the continuous ingestion of new datasets, repeated querying, and the transfer of results. The interface establishes that the system supports these functions, although the video itself does not establish the origin of the uploaded files or the success of any claimed cyberattacks.
Kashef’s Place in the Islamic Republic’s Surveillance Architecture
In its previously published report, “Policy-Making and Institutional Mapping of Citizen Surveillance in the Islamic Republic of Iran”, RaazNet documented how systems such as Shahkar, HAMTA, and SIAM form distinct but interconnected components of the state’s citizen-identification and tracking chain. Shahkar links a phone number to the SIM subscriber’s official identity, HAMTA records the association between a device and a SIM card, and telecommunications infrastructure supplies communications metadata and network-location data to the broader surveillance apparatus.
Citizen Lab’s research into Iran’s mobile lawful intercept system has also shown that the country’s telecommunications regulatory architecture was designed to provide direct access to subscriber information, call and SMS records, and operators’ usage data.
The Kashef video does not demonstrate a direct technical integration with SIAM, Shahkar, or HAMTA, and this connection should not be treated as established. The types of data displayed nevertheless make Kashef’s position at the analytical layer clear: other systems register identity, device, and communications data, while Kashef can transform those fragments into a profile and a graph of relationships.
Kashef’s principal danger does not lie solely in the size of its database. It lies in the system’s ability to turn ordinary traces into a security narrative—one in which an old phone call, presence near an embassy, or contact with a journalist can become the starting point for the next query.

