• Search
  • Tracker
  • Features
  • FAQ
  • Insights
  • About Us
  • Support Us
  1. Search
  2. Results
  3. Organization
Organization

Last Updated: July 19, 2026

  1. Search
  2. Results
  3. Organization

Last Updated: July 19, 2026

Organization

IRANIAN MINISTRY OF INTELLIGENCE AND SECURITY

Aliases

MOIS

VEZARAT-E ETTELA'AT VA AMNIAT-E KESHVAR

VEVAK

Address

bounded roughly by Sanati Street on the west, 30th Street on the south, and Iraqi Street on the east, Tehran, Iran; Ministry of Intelligence, Second Negarestan Street, Pasdaran Avenue, Tehran, Iran

Official reason

Today, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) is designating Iran’s Ministry of Intelligence and Security (MOIS) and its Minister of Intelligence for engaging in cyber-enabled activities against the United States and its allies. Since at least 2007, the MOIS and its cyber actor proxies have conducted malicious cyber operations targeting a range of government and private-sector organizations around the world and across various critical infrastructure sectors. In July 2022, cyber threat actors assessed to be sponsored by the Government of Iran and MOIS disrupted Albanian government computer systems, forcing the government to suspend online public services for its citizens. Today’s action is being taken pursuant to Executive Order (E.O.) 13694, as amended, which targets those who engage in malicious cyber activities. MOIS was previously designated pursuant to Executive Orders 13224, 13472, and 13553 for its support to multiple terrorist groups and for being responsible for, or complicit in, the commission of serious human rights abuses against the Iranian people. The MOIS, under the leadership of Esmail Khatib, directs several networks of cyber threat actors involved in cyber espionage and ransomware attacks in support of Iran’s political goals. In addition to conducting malicious cyber activity that affected Albanian government websites, MOIS cyber actors were also responsible for the leaking of documents purported to be from the Albanian government and personal information associated with Albanian residents. Earlier this year, the United States identified a group of advanced persistent threat (APT) actors, known as MuddyWater, as a subordinate element within MOIS that has been conducting broad cyber campaigns in support of the organization’s objectives since approximately 2018. MuddyWater actors are known to exploit publicly reported vulnerabilities to gain access to sensitive data on victims’ systems, deploy ransomware, and disrupt the operations of private organizations. As recently as November 2021, MuddyWater was assessed to be involved in a cyber campaign targeting Turkish government entities and delivering documents containing malware likely through spear-phishing emails to gain access to victims’ systems. APT39, which OFAC designated pursuant to E.O. 13553 on September 17, 2020, for being owned or controlled by MOIS, is another cyber espionage group that Iran has used to advance its malign objectives. APT39 has engaged in widespread theft of personal identifying information, probably to support surveillance operations that enable Iran’s human rights abuses. Concurrent with the U.S. designation of APT39 and Government of Iran-front company Rana Intelligence Computing Company, the Federal Bureau of Investigation exposed MOIS’ years-long malware campaign that targeted and monitored Iranian citizens, dissidents, and journalists, as well as a host of foreign organizations that included at least 15 U.S. companies. The MOIS is being designated today pursuant to E.O. 13694, as amended, for being responsible for, or complicit in, directly or indirectly, cyber-enabled activity that is reasonably likely to result in, or has materially contributed to, a significant threat to the national security of the United States, and that have the purpose or effect of causing a significant disruption to the availability of a computer or network of computers. Esmail Khatib is being designated today pursuant to E.O. 13694, as amended, for having acted or purported to act for or on behalf of, directly or indirectly, the MOIS.

Sender

US

Additional info

Subject to Secondary Sanctions

Other Information

https://home.treasury.gov/news/press-releases/jy0941

Date of listing

2012-02-16

Program information

Program information

Authority

US

Program

Global Terrorism Sanctions Regulations, 31 C.F.R. part 594

Regime

OFAC-horizontal

Target State

Terrorism

Measures

Blocking Property

Sanctions Portfolio

• https://ofac.treasury.gov/faqs/topic/2396

Official Information

On June 6, 2003, OFAC issued the Global Terrorism Sanctions Regulations, 31 CFR part 594 (68 FR 34196, June 6, 2003 (“the Regulations”), to implement Executive Order (E.O.) 13224 of September 23, 2001, “Blocking Property and Prohibiting Transactions With Persons Who Commit, Threaten To Commit, or Support Terrorism” (66 FR 49079, September 25, 2001). OFAC has amended the Regulations on several occasions. On September 9, 2019, the President, invoking the authority of, inter alia, the International Emergency Economic Powers Act (50 U.S.C. 1701–1706) (IEEPA) and the United Nations Participation Act (22 U.S.C. 287c) (UNPA), issued E.O. 13886, “Modernizing Sanctions To Combat Terrorism” (84 FR 48041, September 12, 2019), effective September 10, 2019. In E.O. 13886, the President, finding it necessary to consolidate and enhance sanctions to combat acts of terrorism and threats of terrorism by foreign terrorists, terminated the national emergency declared in E.O. 12947 of January 23, 1995, “Prohibiting Transactions With Terrorists Who Threaten To Disrupt the Middle East Peace Process” (60 FR 5079, January 25, 1995), and revoked E.O. 12947, as amended by E.O. 13099 of August 20, 1998, “Prohibiting Transactions With Terrorists Who Threaten To Disrupt the Middle East Peace Process” (63 FR 45167, August 25, 1998). In addition, the President amended E.O. 13224, in order to build upon initial steps taken in E.O. 12947, to further strengthen and consolidate sanctions to combat the continuing threat posed by international terrorism, and in order to take additional steps to deal with the national emergency declared in E.O. 13224, with respect to the continuing and immediate threat of grave acts of terrorism and threats of terrorism committed by foreign terrorists, which include acts of terrorism that threaten the Middle East peace process. Section 1 of E.O. 13886 replaces in its entirety section 1 of E.O. 13224, which had been amended by a number of prior Executive orders (E.O. 13224, as amended by all such authorities, is referred to herein as “amended E.O. 13224”), but does not amend the Annex to E.O. 13224, which was previously amended by E.O. 13268 of July 2, 2002, “Termination of Emergency With Respect to the Taliban and Amendment of Executive Order 13224 of September 23, 2001” (67 FR 44751, July 3, 2002) (“amended Annex to E.O. 13224”).

Additional Details

SDN

Program URL

  • https://www.federalregister.gov/documents/2022/07/01/2022-13969/global-terrorism-sanctions-regulations

Have feedback, suggestions or need help navigating sanctions? Let's talk.

Let's discuss how Sanctions Finder can support you or your business or organization.

Product

  • Search
  • Sanctions Tracker
  • Platform Features

Company

  • About Sanctions Finder
  • Insights

Support

  • FAQ
  • Contact Us

Legal

  • Terms of Use
  • Privacy Policy
XLinkedInContact Us

© 2026 Sanctions Finder