Threat Actor Characterization
Mohammad Bagher Shirinkar
ID: 7bfa626f1034b6920c71aa859c6996f481556Actor Network Graph
Open Network GraphMITRE ATT&CK®
Mohammad Bagher Shirinkar is publicly identified as a senior official of Iran's IRGC Cyber-Electronic Command (IRGC-CEC). Open sources also state that he oversees the Shahid Shushtari group and is linked to the wider CyberAv3ngers-associated ecosystem targeting critical infrastructure.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1110 | Brute Force | TA0006 |
|
| T1078.001 | Default Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1491.001 | Internal Defacement | TA0040 |
|
| T1565.001 | Stored Data Manipulation | TA0040 |
|
| T1583.001 | Domains | TA0042 |
|
Classification: TLP:WHITE — Cyber / State-linked / IRGC-CEC-associated official
Author: iQBlack CTI Team
Executive Summary
Mohammad Bagher Shirinkar is publicly identified by U.S. government sources as a senior official of the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). Public reporting does not support treating him as a standalone intrusion persona or distinct threat group; rather, he is best assessed as part of the command-enablement and supervisory layer associated with the broader IRGC-CEC cyber ecosystem.
His name appears in sanctions and rewards material tied to malicious cyber activity against critical infrastructure, and in public reporting that links him to the Shahid Shushtari and broader CyberAv3ngers / IRGC-linked ecosystem. That makes him analytically relevant as an institutional node inside an operational cluster that has targeted OT/ICS-adjacent environments, Israeli-made industrial technology, and infrastructure-related sectors.
Executive Analyst Brief for CISO — Mohammad Bagher ShirinkarClassification: TLP:WHITEWhat this isMohammad Bagher Shirinkar is publicly identified as a senior IRGC-CEC official linked to malicious cyber activity associated with Iran’s broader CyberAv3ngers / critical-infrastructure targeting ecosystem. He is more accurately profiled as an institutional command-enablement figure than as an individually documented operator.Why it mattersProfiles like Shirinkar matter becaus
IOC Appendix — Mohammad Bagher Shirinkar
Scope & Caveats. This appendix is intentionally sparse in hard individual-specific indicators. Mohammad Bagher Shirinkar is best documented as a senior IRGC-CEC official tied to an operational ecosystem rather than as an individually attributed malware author or public-facing operator. As a result, most useful indicators are cluster-level or hunting-oriented, not person-typed blocking indicators.