Actors Insights|Latest update24/07/2026

Nazar

Named by Epic TurlaSuspected state sponsor: Islamic Republic of Iran

Nazar is an Iranian-linked threat actor first identified in April 2020 by researcher Juan Andres Guerrero-Saade through analysis of the NSA's "Territorial Dispute" detection signatures leaked by the Shadow Brokers in 2017. Active since at least 2008, the group operated undetected by the security industry for over a decade, with the NSA having monitored it before 2013. All known Nazar subcomponent samples were submitted to VirusTotal from Iran, and Farsi language artifacts found in the malware's debug paths — including the term "khzer" meaning "to survey or monitor" — point to Iranian origin and likely domestic targeting. The group's modular toolkit includes a dropper that registers DLLs as OLE controls, an orchestrator disguised as svchost.exe, and components for screen capture, microphone recording, keylogging, and a passive network packet sniffer that monitors interface traffic for covert command and control. Check Point's subsequent analysis confirmed the toolkit's use of open-source libraries and assessed the code quality as below the standard of sophisticated state espionage groups, suggesting Nazar operated as a lower-tier surveillance capability possibly directed at targets inside Iran.

First Seen:Jun 2008
Last Seen:May 2020
Indexed Reports:4
Public IOCs:28
Cluster: UnclassifiedMisp: Nazar
also known as:
SIG37 (NSA)Nazar (Epic Turla)

Targeted Regions

Iran
IR
Iran
Iran
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Jan 2008Apr 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.