A Policy-Oriented Think Tank Addressing Foreign Policy and National Security Issues for a Safe Israel

Iran’s Sleeper Networks, False Flags and the ISIS-K Question: How Tehran Operates in the Caucasus and Europe

From Stockholm to Baku, Iran's overseas terrorism doctrine no longer relies solely on Shiite proxies. Criminal gangs, invented groups who claim responsibility for attacks, and possibly even jihadist branding offer Tehran the deniability it needs more than ever
AI-generated illustration

AI-generated illustration

A Toolkit Designed for Deniability

Anyone who still views Iranian terrorism abroad as a Shiite affair carried out by Hezbollah operatives on orders from Tehran is reading from a script Tehran itself abandoned long ago. In 2026, the Islamic Republic’s overseas operations structure looks more like a layered ecosystem than a chain of command: Islamic Revolutionary Guard Corps–Quds Force (IRGC-QF) and Ministry of Intelligence (MOIS) officers at the top, Lebanese Hezbollah and aligned Shiite networks in the middle, and a wide periphery of criminal gangs, sympathizers groomed online, local recruits, teenagers, and—when convenient—Sunni jihadists or non-Iranian actors at the bottom. The point of this architecture is not ideological purity but plausible deniability.

British officials no longer hide their assessment. The UK government’s September 2025 response to the Intelligence and Security Committee’s Iran report stated bluntly that the physical threat posed by Iran has grown sharply since 2022, that MI5 and the police have responded to twenty Iran-backed plots presenting potentially lethal threats, and that Iranian intelligence services increasingly use organized criminal gangs abroad. The same logic is at work in the South Caucasus. In January 2026, Azerbaijan’s State Security Service announced the arrest of three Azerbaijani citizens who had approached a foreign embassy in Baku after entering, in the official phrasing, “criminal relations” with the ISIS Khorasan (ISIS-K) group. Reporting from both Israeli sources and Reuters clarified that the foreign embassy was Israel’s, without verifying the assailants’ possible affiliation.

It is difficult to prove that Tehran orchestrated the January 2026 Baku plot. The available public evidence does not support that conclusion. Yet it is reasonable to suggest that the foiled plot fits a vulnerability Iran has spent years cultivating — one that the IRGC and MOIS would be foolish not to exploit. Sunni extremist branding, Azerbaijani executors, an ISIS-K label, and a target set that overlaps almost perfectly with Iran’s list of enemies create together exactly the kind of attribution fog Tehran prefers. As long as the brand on the bomb says ISIS-K, no one will write the word “IRGC” in an indictment.

Here is a strategic point worth dwelling on: Iranian terrorism abroad does not slow down when Iran is under military pressure. It speeds up. After Operation Epic Fury and Operation Roaring Lion, Persian-language media openly warned that Tehran might activate “sleeper cells” (Selul-ha-ye khafteh) and “silent agents” abroad, and linked that prospect to encrypted communications, criminal proxies, and Sweden’s Foxtrot network. This is the operational logic of Iran’s mosaic-defense doctrine: pressure on the center should not halt activity on the periphery. If anything, the peripheries become more useful precisely when the center is hurting.

Europe: Criminals, Invented Groups and Sleeper Cells

The clearest public demonstration of how Iran’s deniability machine operates in Europe is the Foxtrot case. In March 2024, the U.S. Treasury sanctioned Sweden’s Foxtrot Network and its Iranian-Swedish leader, Rawa Majid, stating that the network had attacked the Israeli Embassy in Stockholm in January 2024 on behalf of the Government of Iran. The British government followed suit, designating the network and declaring that Iran uses criminal gangs around the world to threaten people. It also said Foxtrot had been involved in violent acts targeting Jewish and Israeli sites in Europe on behalf of the Iranian regime. The men who carried out the operation had no Shiite ideology, no theological grievance against Israel, and, in some cases, no real political consciousness at all. What mattered to Iran was that the recruits were ready to act against Israel; at the same time, they may not have known they were working for Iran.

Foxtrot belongs to the criminal-deniability layer of Tehran’s network strategy. A Swedish gang can always be framed, in the first hours of media coverage, as organized crime rather than state terrorism — even when Western intelligence agencies later reveal Iranian commissioning. The fog buys Tehran time. By the time the indictments are unsealed, the story has moved on.

The 2026 HAYI episode points to a second, more sophisticated layer: invented attribution. The International Center for Counter-Terrorism (ICCT) examined a series of attacks against Jewish sites in Belgium, the Netherlands, and the United Kingdom, claimed by a previously unknown group called “Harakat Ashab al-Yamin al-Islamia” (HAYI), and found a digital footprint linked to pro-Iranian militia channels and IRGC-QF-aligned ecosystems. ICCT was careful not to overstate its findings, noting that no unequivocal proof of Iranian involvement existed and that several scenarios remained on the table, including an Iranian hybrid operation, autonomous local cells, or a genuine, independent Shia group. The Anti-Defamation League similarly described HAYI as a newly visible pro-Iran grouping that claimed attacks against Jewish and Israel-linked institutions across Europe, while cautioning that the attacks may or may not have been orchestrated directly by Tehran. 

The relevant analytical point is not whether HAYI is real or fictitious. Rather, it is that a newly created or obscure claiming entity functions, in operational terms, exactly like a false flag. It places a public-facing layer between the attack and its sponsor. Whether the layer is a Sunni jihadist franchise, a Swedish drug gang, or a Shia-sounding acronym no one has heard of, the strategic effect is the same: ambiguity in the headlines, friction in the courtrooms, and breathing room in the chancelleries.

British officials have stopped characterizing this as a future risk. In October 2024, MI5 Director General Ken McCallum stated that since January 2022, MI5 and police partners had responded to twenty Iran-backed plots posing potentially lethal threats. He also said Iranian state actors make extensive use of criminals as proxies, ranging from international drug traffickers to low-level criminals. The British government’s September 2025 response went further, placing the Iranian state, including the IRGC and MOIS, on the enhanced tier of the Foreign Influence Registration Scheme — meaning that anyone, including criminal proxies, whom Iran directs to operate in the UK must register or face prosecution. This is not a deterrent measure for the next decade; it is response to what is happening now.

Baku: A Familiar Target Set Wearing a Sunni Mask

Azerbaijan has been a recurring stage for Iranian operational interest in Israeli, Jewish, and Western targets for more than a decade. In 2012, Azerbaijani authorities accused IRGC-linked networks of plotting attacks against U.S., Israeli, and other Western embassies in Baku. The Iran- and Hezbollah-linked plots in Baku that combined local Azerbaijani recruits with foreign operatives are at the level of modus operandi. They are a reality, not merely an assertion. In March 2026, the IRGC had planned attacks against the Israeli embassy in Baku, a synagogue, Jewish community leaders, and the Baku-Tbilisi-Ceyhan pipeline. Iran offered no immediate comment.

Against that backdrop, the January 2026 detentions are not a stand-alone curiosity. The State Security Service of Azerbaijan said that three Azerbaijani citizens had been arrested after entering criminal relations with the ISIS-K “Vilayati-Khorasan” group, while approaching a foreign embassy. In December 2024, an ISIS-K-affiliated individual received a thirteen-year sentence for plotting a Molotov-cocktail attack on a Baku synagogue. 

Yet the association of ISIS with the plot against the Israeli Embassy in Baku cannot be accepted for granted because it raises some queries:

  •  The Israeli embassy in Baku is a target Tehran has tried to hit for years, and Azerbaijani citizens are exactly the kind of locally embedded operatives Iran prefers.

  • By contrast, in recent years, there have been no ISIS attacks against Israeli embassies. Of course, not because ISIS has any moral qualms about Israel, but because ISIS’s modus operandi is to target “the nearest enemy,” meaning local Muslim governments and compatriots, considered “apostates”.

  • ISIS always prefers spectacularity, which an attack on Israeli targets cannot provide.

  • Usually, ISIS attacks are carried out by local Sunni sympathizers in an environment they are perfectly familiar with. It is highly unusual for ISIS to deviate from its modus operandi and act in a Shi’ite-majority secular country, which is secondary in ISIS’s vision.

  • When the operational label is ISIS-K, the target is Israel, the executors are local, and the geography is Iranian-adjacent, the false-flag or cutout hypothesis cannot be dismissed merely because it is uncomfortable.

Hostile Enemy, Exploitable Brand, or Compartmented Contact?

To be clear, ISIS-K is a real adversary of Iran, not a fictional Iranian creation. ISIS-K has killed or wounded hundreds of people in Afghanistan, Iran, Pakistan, and Russia. The Jihadi group accepted responsibility for the January 2024 Kerman bombing — which struck a commemoration for the assassinated IRGC-Quds Force commander Qassem Soleimani and killed more than eighty people. The Kerman bombing is part of ISIS-K’s broader operational pattern that frames Iran as a Shiite aggressor against Sunnis. The bombings of the Iranian parliament and Khomeini’s shrine in 2017, the two attacks on the Shah Cheragh shrine in Shiraz in 2022 and 2023, and the carnage at Kerman in early 2024 are not the work of an Iranian asset. They are the work of a movement that considers Shiites apostates and the Islamic Republic the vanguard of the so-called “rāfeḍī” — the alleged Shiite-Iranian conspiracy to dominate the Sunni Muslim world.

That hostility is the central caveat. ISIS-K has its own ideology, external operations networks, recruitment pipelines in Tajikistan and across Central Asia, and media output via Al-Azaim and affiliated channels. Yet Iranian intelligence organs could use ISIS-K-linked individuals, ISIS-K branding, or jihadist-adjacent intermediaries to advance a state interest while preserving deniability. ISIS-K itself did not issue any statement regarding the affair.

The al-Qaeda Precedent: Tehran’s Quiet Guests

The U.S. State Department’s 2023 Country Reports on Terrorism state that Iran has hosted senior al-Qaeda leaders and allowed an al-Qaeda facilitation pipeline through its territory, even though al-Qaeda is a Sunni jihadist organization ideologically hostile to Shiism. The most prominent figure is Sayf al-Adl, frequently described as al-Qaeda’s de facto operational leader and reportedly residing in Iran under Quds Force supervision. Hamza bin Laden, the late son of Osama, spent years in the Islamic Republic. Abu Asim al-Muhajir, an al-Qaeda operational planner, has been described in U.S. and UN reporting as having used Iranian logistical facilities for cross-border operations.

Tehran denies these reports. A 2025 UN document records Iran’s categorical denial that Sayf al-Adl or any other al-Qaeda member is present on Iranian soil, and Iran rejected allegations that it finances al-Qaeda or that it has a strategy to activate sleeper cells in the EU, Syria, Lebanon, or Afghanistan. The denial itself is part of the evidentiary record. The pattern that emerges from the al-Qaeda case is one of “realpolitik in religious dress”: ideological hostility on the public stage, instrumental cooperation in the back rooms, and plausible deniability when something is exposed.

The al-Qaeda precedent does not automatically apply to ISIS-K. The two Sunni jihadist movements are enemies, and ISIS-K’s ideological war against the Islamic Republic is more direct and more violent. Moreover, it is worth noting a very important, albeit forgotten, nuance: al-Qaeda has never been hostile to Shi’ites or Iran. However, the precedent does establish something important: the Islamic Republic has demonstrated, on the record, that it can interact with, host, transit, and even tolerate the presence of Sunni jihadists when the alternative is being unable to project pressure against the United States or Israel.

False-Flag Mechanics and the Persian Debate

False-flag logic does not require Tehran to control an organization. It requires only partial manipulation: a cutout, a recruiter, an arms supplier, or a target package handed to someone who already wanted to attack. In a plausible Iranian model, the actual attacker may genuinely believe he is acting for ISIS-K, a criminal gang, a local extremist cell, or an invented group. In contrast, an Iranian handler or facilitator shapes the operation from a distance — by curating the target list, selecting the timing, or amplifying the claim afterward through pro-Iranian channels.

This is precisely the framework now being discussed in Persian-language analytical circles, including by figures who are no friends of the Islamic Republic. A Persian-language interview on YouTube features the religious researcher and political analyst Mohammad Lahmi, who argues that the Islamic Republic’s relationship with extremist groups should not be viewed solely through the lens of military and ideological confrontation. Lahmi describes a forty-five-year behavioral pattern in which Tehran cooperates with groups such as ISIS-K or Jaish ul-Adl whenever it serves the regime’s interests — not on ideological grounds, but as a tactical necessity for managing threats and exporting instability. In his framing, Iran adopts diplomatic and anti-terrorism postures in public while quietly using radical groups to challenge the regional order.

The Persian-language debate over false-flag operations on Iranian soil intensified after the first Shah Cheragh attack in October 2022, which struck the Shi’ite shrine on the 40th day of mourning for Mahsa Amini, at the height of the “Woman, Life, Freedom” protests and amid severe domestic and international pressure on the regime. Iranian dissidents and analysts argued that the regime stood to gain from such attacks: they polarized society, allowed the authorities to portray protesters as paving the way for Sunni terrorism, and shifted the public conversation from political rights to security. The attack’s operational pattern diverged from ISIS’s usual modus operandi, raising questions about whether the authorities had foreknowledge of or facilitated the timing. The same questions resurfaced after the second Shah Cheragh attack in 2023 and even, in some quarters, after Kerman. However, in the Kerman case, the evidence of an ISIS-K external operation is far more solid.

The Shah Cheragh and Kerman attacks killed Iranian civilians — Iranian Shiites — and there is no public evidence that Tehran orchestrated them. What the Persian-language debate establishes is something different: the Iranian public, including its dissidents, does not find the false-flag hypothesis inherently implausible when applied to the Islamic Republic. That public mood matters. It shows that the very ambiguity Tehran cultivates abroad has a domestic counterpart and that Iranians themselves struggle to draw a clear line between the regime’s enemies and its instruments.

“Managed Enmity”: Iran, the Taliban, and the Tajik Pipeline

Beyond the false-flag question, there is the broader structural relationship between Tehran and ISIS-K, which the Persian analytical literature increasingly characterizes as “managed enmity” (doshamni-ye modiriyat-shodeh). The military confrontation is real at the operational level. At the strategic level, however, the regime derives political utility from the threat itself.

Since the Taliban’s return to Kabul in August 2021, ISIS-K has exploited the security vacuum to rebuild its networks — and Iran has used ISIS-K as a kind of “security scarecrow” to pressure the Taliban. Tehran benefits from a policy of “controlled instability” on its eastern flank: ongoing ISIS-K activity forces the Taliban to cooperate with Iran on security, prevents the consolidation of a strong, unified Sunni state on Iran’s borders, and sharpens friction between Kabul and Islamabad. Some intelligence reporting suggests that certain ISIS-K cells in border regions may be in indirect contact, through local intermediaries, with regional intelligence services that share an interest in selectively targeting Chinese, Russian, or other diplomatic interests. None of this proves command and control. It does suggest that the presence of a hostile Sunni jihadist movement next door is, for the Islamic Republic, a problem that can sometimes be put to work.

The Tajik dimension is the part of this picture most relevant to Israeli, Caucasian, and European security. ISIS-K’s recruitment of ethnic Tajiks has accelerated dramatically since 2022, and the cultural-linguistic affinity among Persian, Dari, and Tajik gives the Khorasan branch an unusual ability to penetrate Iranian territory. The Kerman attackers were Tajik. Recruitment occurs through online media, including ISIS-K’s Al-Azaim outlet, which broadcasts in Tajik and Persian; training takes place in Nangarhar and Kunar; and, in many recent cases, transit goes through Turkey on forged documents. The same pipeline that delivered attackers to Kerman could, in principle, deliver attackers or their handlers to Baku. Whether the Islamic Republic’s security services demonstrate “genuine inefficiency” or “deliberate forbearance” regarding these flows is a question Iranian analysts now ask out loud.

Russian and Iranian readings of the Khorasan threat, incidentally, do not align as neatly as the Moscow–Tehran partnership often suggests. After the March 2024 Crocus City Hall attack, the Kremlin tried to deflect attribution to Ukraine, despite clear ISIS-K responsibility, leaving some in Tehran feeling that their concerns about Sunni jihadist terrorism were being subordinated to Russia’s information needs. The Russia–Iran alliance is real but bounded; on terrorism attribution, both sides are willing to manipulate the narrative to suit their interests.

Conclusion: Watch the Network, Not the Label

The most honest analytical posture on the January 2026 Baku case is a careful one. There is no public evidence that Iran directed the plot. The official Azerbaijani attribution is to ISIS-K, and Azerbaijani authorities are serious counterterrorism actors. Yet the target, geography, timing, and executor profile fit a broader Iranian target set in Azerbaijan with uncomfortable precision. And the ISIS-K label, if a hidden Iranian role were ever proven, would offer Tehran the strongest possible denial. The correct intelligence posture is therefore not to assert a proven Iran–ISIS-K command link, but to investigate whether Iranian actors exploited ISIS-K-linked individuals, jihadist branding, criminal intermediaries, or a Sunni cover story to advance the same target set that Iran has pursued in Baku for over a decade.

The same logic applies across the European theater. Foxtrot shows that Iran will commission attacks on Israeli embassies through Swedish criminals. HAYI shows that Iran’s network can produce, or at a minimum amplify, an invented, Shia-sounding claimant group when it suits Tehran’s information environment. Whether the next layer is an ISIS-K-branded cell in Baku, an Azerbaijani petty criminal in Berlin, or a teenager in Manchester groomed online by an Iranian handler is, in operational terms, a matter of which mask is most convenient on a given day.

Three operational implications follow. First, Western and Israeli services should monitor not only IRGC-affiliated Shiite networks but also Sunni extremists, criminals, online-groomed lone actors, teenagers, diaspora intermediaries, and obscure or invented claimant groups that may serve as operational masks for Iranian state violence. The traditional analytical divide between “Shiite Iranian terrorism” and “Sunni jihadist terrorism” is obsolete as a counterterrorism framework; Iran has long since abandoned it.

Second, indicators to watch closely include financial transfers from Iranian-linked individuals or criminal networks to ISIS-K-linked suspects; communications between detainees and accounts previously tied to Iranian, Iraqi militia, Hezbollah, or Houthi ecosystems; the locally recruited, weakly ideological executor profile that characterized both Foxtrot and HAYI; claims of responsibility that are first amplified by pro-Iranian channels rather than by ISIS-K’s normal media ecosystem; and the combination of Israeli or Jewish targets with Azerbaijani energy infrastructure or dissident targets. The repetition of “sleeper cell” rhetoric in Persian, Arabic, or militia-linked channels after Iranian military setbacks should be read not only as psychological warfare but also as a possible mobilization signal.

Third — and this is the recommendation most relevant to Israeli policy — the assumption that a militarily weakened Iran will reduce its overseas violence is the exact opposite of the reality on the ground. Pressure on the regime makes deniable retaliation more attractive, not less. The mosaic-defense doctrine is designed precisely for the situation Iran faces after Operations Epic Fury and Roaring Lion: degraded central command but persistent peripheral activity. Israel and its partners should therefore expect more attempted Foxtrots, more attempted HAYIs, and possibly more attempted Bakus — not fewer. The label on the next attack will probably not read “IRGC.” That is the entire point of the strategy.

Iran’s terrorism doctrine in 2026 is adaptive, deniable, and opportunistic. It does not rely on Shiite followers, formal proxies, or ideologically loyal militants. It relies on networks. So should Israel and the West’s response.


JISS Policy Papers are published through the generosity of the Greg Rosshandler Family.


Picture of Maj. (res.) Alexander Grinberg

Maj. (res.) Alexander Grinberg

Capt. (res.) in the IDF Military Intelligence research department. Holds degrees in Middle East and Islamic studies, and Arab language and literature, from the Hebrew University of Jerusalem. Doctoral student in Iranian history at Tel Aviv University.

Recent publications

Security Through Economics: Regional Infrastructure as a Lever for Stability

Long-term security depends not only on preventing threats but also on shaping shared interests. Economics,...

Mapping the Middle East’s Game of Camps

The multi-front war has altered the balance within and between the region’s rival camps, requiring...

Halting Arms Sales to Qatar Is Only the First Step

Israel’s decision to end defense exports to Qatar addresses only part of the problem. Doha...

By signing up, you agree to our user agreement (including the class action waiver and arbitration provisions), our privacy policy and cookie statement, and to receive marketing and billing emails from jiss. You can unsubscribe at any time.

Sign up for the newsletter

For up-to-date analysis and commentary.

Are You In?

Join 8,000+ Subscribers who enjoy our weekly digest