Reports Archive:
Research & Analysis

A comprehensive collection of technical reports, security analyses, and in-depth research. Exploring the depths of digital security with a critical lens.

Sort:
Unraveling the Islamic Republic’s Quarter Century Quest for Spherical ImplosionDestructive Cyber Operations
25 min read
Was Fast16 the malware that struck at the core of the Islamic Republic’s implosion type nuclear weapons program, beyond what Stuxnet ever targeted?
Read Report
Filimo: How Iran's Leading Streaming Platform Exposes Users to Credential Theft and Cross-Border ProfilingCitizens Privacy Rights
9 min read
A privacy audit of Filimo reveals plaintext credential storage, global analytics transmission, and embedded location surveillance, all operating within Iran's compelled-access jurisdiction where no independent data protection authority exists
Read Report
The New Map of Tiered Internet Access in IranDigital Censorship & Repression
25 min read
From White Lines to Internet Pro: Reselling Blacklist Censored Internet to Authenticated Users
Read Report
Bitbaan Anti-Malware: When a Security App Becomes a Liability in Iran's Surveillance LandscapeCitizens Privacy Rights
9 min read
A privacy audit of Bitbaan Anti-Malware reveals hidden camera capture, weak password encryption, network scanning, and extensive tracking, privacy failures that are particularly dangerous in an app that Iranian users trust to protect them, operating within a jurisdiction with no independent data protection oversight
Read Report
BadeSaba Calendar: Privacy Risks of a Calendar App Operating Under Iran's Surveillance FrameworkCitizens Privacy Rights
8 min read
A blackbox privacy audit of BadeSaba Calendar reveals aggressive tracking and broken cryptography, vulnerabilities made far more consequential by the app's operation within a jurisdiction where the state maintains documented capabilities to compel data access without independent oversight
Read Report
Attack Without a Hack: How a Piece of Malware Took the MahsaAlert Domain Off the InternetDestructive Cyber Operations
17 min read
Attackers created a piece of malware and registered the MahsaAlert domain as its C2 server, deceiving global security systems and causing this civil alert platform to be blocked.
Read Report
How Iran’s National Information Network WorksSurveillance Policy & Regulation
28 min read
With the internet in Iran shut down by the government of the Islamic Republic in January 2026, a familiar question resurfaced: Is the country becoming North Korea?
Read Report
Policymaking and Institutional Mapping of Surveillance and Interception of Citizens under the Islamic Republic of IranSurveillance Policy & Regulation
24 min read
How Centralized Authentication, Infrastructure Level Monitoring and Interception, Spyware Operations, and Street Level Surveillance Have Converged into a Unified System for Controlling, Suppressing, and Intercepting Citizens
Read Report
Jamming in Iran: The Business of Disruption and the Defense Contractor NetworkTechnology Supply Chains
28 min read
Examining the Role of Ofogh Saberin Co in Iranian Ministry of Defense Jamming Projects and the Export of Digital Repression Technologies
Read Report
Charming Kitten (APT35) Modular Windows TrojanDestructive Cyber Operations
6 min read
Persistent Access and Covert Command and Control within the Islamic Republic of Iran’s Surveillance and Interception Architecture
Read Report
RAT-2Ac2: A Report on a State-Aligned Remote Access ToolDestructive Cyber Operations
4 min read
Examining the Organizational Logic, Operational Architecture, and the Role of a Modular RAT in Charming Kitten’s Covert Digital Surveillance
Read Report
Say Cheeeese!Destructive Cyber Operations
10 min read
An Android spyware called Aks-e Yadegari (Souvenir Photo) is spreading through Telegram, targeting Iranian cryptocurrency exchanges.
Read Report