US Puts a 0 Million Bounty on IRGC-Linked Cyber Operatives as Global Threat Escalates

Listen to this Post

Featured Image

🎯 Introduction

The quiet war unfolding in cyberspace has erupted into a public confrontation. The United States has taken an aggressive step against an elite Iranian hacking unit accused of infiltrating critical infrastructure around the world. With a staggering $10 million reward now on the table, Washington is signaling that the digital battlefield is no longer a hidden arena but a frontline crisis demanding global attention. The story unfolding behind this manhunt reveals a darker reality about modern conflict, one where keystrokes can sabotage pipelines, steer elections and destabilize entire industries.

Main Summary — Full Context and Expanded Analysis (approx. 30 lines)

A global spotlight has been cast on Shahid Shushtari, a clandestine cyber unit operating under the Iranian Revolutionary Guard Corps Cyber-Electronic Command. U.S. officials accuse the group of orchestrating wide-scale hacking campaigns targeting critical infrastructure in the United States, Europe and the Middle East. In an effort to disrupt their operations, the State Department has announced a reward of up to $10 million for information leading to the capture or identification of two key actors: Mohammad Bagher Shirinkar and Fatemeh Sedighian Kashi.

The pair, believed to be closely intertwined with the leadership of Shahid Shushtari, allegedly worked together to coordinate digital attacks directly benefiting the Iranian regime. The State Department’s Rewards for Justice program even issued a blunt message to the public: “Help us take the smile off their faces,” a rare expression of urgency from officials typically measured in tone. This message underscores the seriousness of the threat. Shahid Shushtari is not an isolated or small-scale organization. According to cyber intelligence experts, it serves as the latest incarnation of Emennet Pasargad, a group previously sanctioned for meddling in the 2020 U.S. presidential election.

Experts like Josh Atkins at Google’s Threat Intelligence Group have tracked the unit for years under the designation UNC5866. He describes it as an entity that constantly shifts identities, operating under several front companies including Aria Sepehr Ayandehsazan, Net Peygard Samavat Co., and Eeleyanet Gostar. These cover identities reflect a sophisticated survival strategy: mask the group, rebrand, evade sanctions, and continue attacking.

The impact of this cyber unit is enormous. Officials report that Shahid Shushtari has targeted sectors ranging from finance and shipping to energy, telecom and media. Their tactics span phishing campaigns, malware delivery and elaborate influence operations designed to manipulate public opinion. In 2020, the group allegedly used impersonation, intimidation emails and false-flag personas to interfere with the U.S. presidential election. Beyond politics, the unit has launched operations aimed at espionage, disruption and strategic advantage for the Iranian state.

The Treasury Department formally sanctioned Emennet Pasargad and six of its members in late 2021 for their election interference efforts. Yet despite these actions, the group remained active, adopting new tradecraft and refining their techniques into 2023 and 2024. A joint advisory from the FBI, Treasury Department and Israel’s National Cyber Directorate described the group as adaptive and persistent, showing no sign of slowing down.

Atkins notes that their operational tempo has remained consistent since 2020, with ongoing phishing and malware operations at a steady pace. He also emphasizes that groups like this, especially those under IRGC oversight, tend to be reactive. Their fast-evolving tactics reflect a regime that prioritizes quick, opportunistic offensive measures rather than long-term strategic planning. As cyber operations increasingly resemble military campaigns, the hunt for Shirinkar and Kashi illustrates just how seriously digital warfare is now treated on the world stage.

What Undercode Say:

The escalating pursuit of Shahid Shushtari’s leadership marks a pivotal moment in cyber geopolitics. To understand the broader impact, it’s essential to examine how Iran’s cyber infrastructure, global intelligence partnerships and modern warfare intersect. At its core, this manhunt exposes a strategic shift: governments are no longer whispering about cyber conflict. They are naming actors, offering massive rewards and treating hackers as high-value fugitives.

Iran’s IRGC cyber apparatus has matured into a hybrid force, part intelligence agency and part digital strike team. Unlike traditional military branches, these cyber units can inflict damage without deploying soldiers, crossing borders or risking airstrikes. They operate through disguise, deception and relentless experimentation. Their attacks on critical infrastructure highlight a chilling reality. A well-placed malware script can shut down a hospital, freeze a bank’s systems or obstruct energy pipelines. Every sector targeted by Shahid Shushtari shares a common thread: disruption causes chaos that extends far beyond digital boundaries.

The fact that this group repeatedly changed identities shows how effective international sanctions can be. Every name change reflects an attempt to outrun accountability. Yet the persistent rebranding also exposes a vulnerability. When a unit must constantly shed its identity, it creates operational friction, strains internal communication and complicates coordination. This perpetual disguise is both a shield and a weakness.

The decision to place a $10 million bounty on Shirinkar and Kashi suggests U.S. intelligence may believe the group is preparing for more ambitious operations. Rewards of this size are typically reserved for high-risk actors capable of inflicting national-level harm. That alone illustrates how seriously these hackers are taken. Their historical involvement in election interference makes them particularly dangerous. Influence operations combine psychological manipulation, data theft and disinformation. They are harder to detect, easier to deny and capable of destabilizing democracies without firing a weapon.

Iran’s cyber activity also aligns with a broader geopolitical narrative. As the global landscape shifts, cyber warfare becomes a preferred tool for nations seeking influence without triggering direct military conflict. The United States, China, Russia and Iran all understand this new calculus. Digital campaigns are cheaper, faster and less traceable than traditional warfare. They also exploit humanity’s growing dependence on interconnected systems.

The continuing involvement of Israel’s cyber directorate underscores the regional stakes. Iran’s cyber expansion is viewed not only as a threat to the West, but also as part of a larger Middle Eastern power struggle where critical infrastructure is increasingly militarized. Cyber units like Shahid Shushtari embody this evolution. They operate in the shadows but shape visible geopolitical tension.

Meanwhile, the consistency of UNC5866’s attack patterns paints a picture of an organization operating with both autonomy and political support. Their pace suggests they are embedded within the IRGC ecosystem, receiving directives, targets and resources. Their persistence reveals a long-term strategy disguised within short-term reactivity.

In the broader cyber landscape, this case highlights a global truth: digital warfare has no borders, no soldiers and no time zones. It’s a perpetual battlefield where the line between espionage and sabotage is blurred. The chase for Shirinkar and Kashi is not only about catching two individuals. It’s a symbolic stand against the normalization of government-sponsored cyber aggression.

🔍 Fact Checker Results

The $10 million reward for Shirinkar and Kashi is officially confirmed by the U.S. State Department. ✅

Shahid Shushtari is verified as an alias of Emennet Pasargad, sanctioned in 2021. ✅

The group’s role in the 2020 U.S. election interference is documented in Treasury records. ✅

📊 Prediction

The hunt for these IRGC-linked hackers will intensify as global cyber conflicts escalate. 🔮
Expect more public exposure of Iranian cyber units, alongside new sanctions and joint international advisories. 🌍
Future cyberattacks may become more aggressive as state-sponsored groups evolve under mounting pressure. ⚡

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberscoop.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon