Another great write-up on APT35 from Iran International, where they go over the variety of activity attributed to the IRGC. Department 40, known more commonly in the cybersecurity sphere as Charming Kitten, is an IRGC intelligence arm of cyber terrorists conducting phishing attacks, data exfiltration, and spying on both other nations and their own citizens abroad. Department 40 and other groups within the IRGC attem…

Channel
ByteSec1401 Efshagari
@ByteSec1401_Efshagari
On this record: Growth · Engagement · What this channel posts · Reactions · Posts · Citations · Cite this entry
67subscribers
+0 since we began measuring on 24 August 2026
Risers and fallers across the register · movement among entries of Under 1,000.
Register entry
| Telegram ID | -1002474968499 |
|---|---|
| Type | Channel |
| Username | @ByteSec1401_Efshagari |
| Description | Admin: @Leila97726926 |
| Created | Between 1 September 2024 and 13 February 2025 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 24 August 2026 |
| Last confirmed live | 11 September 2026 |
| Measurements held | 2 |
| On Telegram | t.me/ByteSec1401_Efshagari |
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 24 Aug 2026, 11:45 | 67 | no change |
| 24 Aug 2026, 11:30 | 67 | first reading |
Engagement
20 posts held, back to 13 February 2025 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 page of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 24 November 2025. An engagement rate over an empty window would be a number about nothing.
What this channel posts
- Photos
- 2
- Links
- 33
Lifetime counters from Telegram’s own channel header, read 24 August 2026 — not the date at the top of this page, which is when the subscriber count was last read. Below Telegram’s rounding threshold, so these counts are exact.
Reaction mix
2 reactions across 2 posts, in 2 distinct kinds. The most used accounts for 50.0% of them.
| Reaction | Count | Share | Share, drawn |
|---|---|---|---|
| ❤ | 1 | 50.0% | |
| 👎 | 1 | 50.0% |
No sentiment is inferred, and none should be read in. This table is ordered by count and by nothing else. Emoji do not carry stable meaning across languages or communities — 🙏 is thanks in one channel and mourning in another — so we publish which ones were pressed and how often, and pass no judgement on what an audience meant by them.
Precision. Telegram publishes reaction counts per emoji and short-forms each one — 4.34K, 1.2M — so any single kind at or above 1,000 reaches us at three significant figures, and only counts below 1,000 are exact. The shares above are ratios of those figures and carry the same error. This is also why the total here can differ slightly from a reaction total printed elsewhere on the page: both are sums of the same rounded parts, taken over samples with different edges.
Coverage. Reactions were read on 4 of the 20 sampled posts in this sample. Summed by Telegram’s own count on each post — not by adding up the per-emoji breakdown above — those same posts carry 2 reactions in total: the kind of figure the paragraph above means by “a reaction total printed elsewhere on the page”.
Measured over the 20 most recent posts we hold, published 13 February 2025 to 24 November 2025, using the newest reading held for each. Telegram Stars are excluded: they are a payment, not a reaction, and they have their own section.
Recent posts
زمانی که ما سرمون شلوغ بود با افشاگری دست نشانده سپاهی، دوستانمان به ما خبر دادن که آقای میلاد رهنما و شرکت داده نگارتصمیم گرفتن به حمایت از سپاه ادامه بدن. تازه چی.. دوستای سپاهی احمقش هم فکر کردن میتونن کمکش کنن با قایم موشک بازی و جابه جایی محل کار و بهش اجازه بدن تا به ظلم کردن مردم مظلوم ایران ادامه بده. شاید دوست داشته باشن بدونن نظرشما راجع به آنها چیه؟ یک سری بهشون تو خیابون فریدون خانی بزنید! ما را در ایکس…
It's been nearly a month since the end of the 12 day war, but to see a report this detailed on the activity of the regime's peons already is astounding. Of the 74 different "hacktivist" groups being observed, 67 of them were pro Iranian which all but means they're funded by the junta. As always, most of the attacks involved distributed denial of service, website defacement, and data leaks, and most of the targets inc…
Once again the MOIS aligned APT39 "Remix Kitten" is getting called out in the news for stealing peoples' sensitive data. The hacker group was discovered to be operating in compromised airlines such as the Iranian company Amnban. During this they successfully harvested millions of PII globally belonging to airline customers such as their home addresses and passport numbers. It's clear that this wasn't done for only fi…
👎1
It may be too early to say it outright, but if this article is to be believed, it looks like Emennet Pasargad, an APT we have discussed thoroughly in the past, may be in league with or possibly be today's organization of interest, Cyber Isnaad Front. This is further backed up by their effects and pattern of behavior matching up with not only Emennet Pasargad but also Al-Qassam Brigades, the military wing of the terro…
https://gbhackers.com/state-sponsored-hackers-now-widely-using-clickfix-attack/ It may be a new year, but old tricks seem to not die with the Iran regime, who according to Proofpoint, is using a social engineering method called Clickfix. This is a social engineering technique that displays fake error messages and security alarms seemingly from the OS or other apps a user would be familiar with. This tricks users in…
https://nationalinterest.org/feature/australia-must-join-maximum-pressure-against-iran A decent read on Iran once again interfering in the day to day of another country, only said country is only meeting their threat halfway. While the Australian government has levied sanctions against Iran for their crimes including taking people hostage, trying to steal information to create a nuclear weapon, and using cyber crime…
❤1
https://themedialine.org/top-stories/how-iran-spies-and-how-women-activists-stay-one-step-ahead/ We know Iran has been using tech to supress voices they don't like, but their endeavors in cyber control marks a new low for the regime. On top of using spyware and monitoring social media interactions, the Iranian government integrates data from sources such as facial recognition and encrypted communications, meaning th…
https://www.specialeurasia.com/2025/03/24/iran-ai-silicon-persia/ This report from SpecialEurasia goes into how the IRGC has been using AI technology to help with their cyber infrastructure. In the article, the IRGC has been said to have committed $115 million into AI research and development this year, to supplement their other activities. As of 2 weeks ago even, they released their own AI platform, as well as plan…
https://industrialcyber.co/news/cydome-analyzes-lab-dookhtegan-cyber-attack-on-iranian-oil-tankers-provides-mitigation-action/ The cracks in Iran's armor are beginning to show. According to Cydome's martime cyber research team, Lab Dookhtegan was able to hack into the communication infrastructure of 116 oil vessels belonging to two companies owned by the Iranian government. This was likely done by Lab Dookhtegan dis…
https://petroleumaustralia.com.au/news_article/dragos-report-reveals-escalating-cyber-threats-to-industrial-sector/ A dire article on the escalation of ransomware which is up 87% from last year, and with it comes new malware designed specifically for operational technology environments. So much so, that many critical industries such as water, energy, food, and chemical engineering have all been targeted by state spo…
https://slguardian.org/iranian-hackers-leak-israeli-gun-owners-data-in-unprecedented-cyber-breach/ A massive cyber security breach in Israel occurred against their citizenry, that includes four terabytes worth of stolen data revealing their identities, home addresses, and their status as gun owners. A "pro Palestinian" group called Handala is claiming to be behind the leak to be behind the leak and are believed to b…
Showing the 12 most recent of 20 posts we hold for @ByteSec1401_Efshagari. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Forward network
Republishes
Channels on the register whose posts this channel has forwarded.
Built only from forwarded posts we have actually read, on both sides. Coverage is early and deliberately incomplete: a missing link means we have not read the post that would prove it, never that the relationship does not exist. Counts are distinct forwarded posts observed, so they only ever go up as we read more.
Mentions
Named by 1 registered channel — every channel on the register whose own posts have named this one, by its current username or any other username it currently holds, merged from two separately captured readings of the same fact so a namer caught by only one of them is not missed and a namer both caught is not counted twice. A username this channel has since dropped is not matched — that handle may belong to someone else now, and crediting today’s namer to yesterday’s owner would misattribute it.
Named by
Channels on the register whose posts name this channel's handle.
A mention is a weaker signal than a forward and is counted separately for that reason — naming a channel is not republishing it, and a handle in a post body is easy to place deliberately. The post counts beside each row below are distinct posts in which the handle appeared, from posts we have read on both sides — the “Named by N registered channels” figure above is a different count, of distinct NAMING CHANNELS rather than posts, and is not the sum of the rows under it.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 24 August 2026 — this entry's latest reading, not the date you are reading this.
“ByteSec1401 Efshagari” (@ByteSec1401_Efshagari), 67 subscribers as measured 24 August 2026. Telegram Register, tgregister.com/channel/ByteSec1401_Efshagari.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.