Man spying from his car
Man spying from his cariStock

Erfan Fard is a counterterrorism analyst and Middle East studies researcher based in Washington, with a particular focus on Iran, Islamic Terrorism, and ethnic conflicts in the region. His father, mother, and two brothers live in Iran. His latest book is The Black Shabbat , published in the US. You can follow him at erfanfard.com and on X @EQFARD or www.ErfanFard.com.

For decades, the Islamic Republic of Iran built its power abroad through recognizable instruments: the Islamic Revolutionary Guard Corps, the Quds Force, Hezbollah, Shiite militias, intelligence officers, diplomatic cover, and well-financed proxy organizations. But one of the most disturbing revelations about Tehran’s contemporary security apparatus is that its next operative may look nothing like a terrorist. He may be an ordinary person sitting thousands of miles from Iran, communicating through Telegram, accepting a small cryptocurrency payment for an apparently trivial assignment, and having little idea where the relationship will ultimately lead.

That is what makes the reported activities of Unit 4000 so important. The unit, also described as the Special Operations Division within the IRGC Intelligence Organization, represents a more clandestine side of Iranian power projection. Unlike the Quds Force, whose relationships with established militias and armed proxies are widely known, Unit 4000 has been publicly identified by Israeli intelligence as an apparatus for covert operations abroad: recruiting and directing operatives, gathering intelligence, preparing attacks, moving weapons, and targeting Israeli, Jewish, and Western interests.

The significance of Unit 4000 is therefore larger than the existence of another secret department inside the IRGC. It represents an evolution in the economics and tradecraft of state-sponsored terrorism. Tehran no longer needs every operative to be an ideological revolutionary, trained intelligence officer, or committed member of an established terrorist organization. The reported model increasingly depends on distance, deniability, digital communications, local intermediaries, criminal contacts, and individuals who can be recruited where an operation is intended to occur.

The recruitment process is particularly disturbing because of its potential simplicity. According to reporting on Iranian intelligence activity, prospective recruits can be approached online, including through Telegram, and initially offered small cryptocurrency payments for seemingly limited tasks. The progression may begin with information gathering, photography, locating an address, verifying whether a person lives at a particular location, or observing a site. The recruit is paid. Trust is established.

The next assignment becomes more sensitive. Over time, what appeared to be easy money can evolve into surveillance, intelligence collection, logistical support, sabotage, or assistance to an operational network. This is recruitment by escalation.

Its effectiveness lies precisely in the fact that the recruit does not necessarily have to embrace the ideology of the Islamic Republic. Money can substitute for ideology. Criminality can substitute for loyalty. Digital communication can substitute for the traditional relationship between a case officer and an agent. Cryptocurrency can complicate the financial trail, while compartmentalized assignments can prevent a recruit from initially understanding the larger operation.

This model also creates layers of plausible deniability. An individual photographing a building does not look like an IRGC officer. A local criminal purchasing equipment does not look like an Iranian intelligence operative. A migrant recruited to conduct surveillance may not know the identity of the ultimate commander. Yet when those seemingly disconnected actions are coordinated from inside an intelligence structure, they can form pieces of a state-directed operation.

The public exposure of Unit 4000 in April 2026 offered an unusually detailed picture of that architecture. Mossad, Shin Bet, and the IDF identified the unit as part of the IRGC Intelligence Organization and described Rahman Moghadam as the head of its Special Operations Department. Mohsen Suri was identified as a senior operator who traveled abroad, met local cells, and directed missions. Majid Khademi, the head of IRGC Intelligence, stood above the apparatus. Israeli intelligence said these senior figures were killed during the military campaign against Iran.

But killing commanders does not automatically destroy a method.

The Azerbaijani case demonstrates why. Authorities disrupted a network reportedly preparing attacks against the Baku-Tbilisi-Ceyhan oil pipeline, the Israeli Embassy, a synagogue in Baku, and Jewish community figures. Investigators recovered explosive material, explosive drones, and fragmentation charges, while the cell had conducted surveillance and photography of potential targets. Israeli authorities subsequently linked the network to Unit 4000 and said its handlers operated from Iran.

The target selection reveals the breadth of the unit’s mission. This was not simply an assassination apparatus. Energy infrastructure, diplomatic facilities, religious institutions, community leaders, military installations, and strategic sites all fell within the reported operational universe. Other disclosed activity linked handlers associated with the network to Turkey and Cyprus, including the smuggling of explosive drones and intelligence collection involving Incirlik Air Base.

The deeper lesson for Western intelligence services is that countering Unit 4000 cannot mean searching only for Iranian intelligence officers. The operational perimeter is much wider. Investigators must examine the connective tissue between Iranian handlers and local facilitators: unusual cryptocurrency transfers, online recruitment, repeated surveillance of sensitive sites, criminal intermediaries suddenly performing intelligence-like tasks, attempts to acquire dual-use technology, unexplained photography of diplomatic or military facilities, and individuals receiving progressively more sensitive assignments from contacts whose identities they may not fully understand.

Analytical discipline remains essential. A Telegram conversation is not evidence of terrorism. A cryptocurrency payment does not prove Iranian direction. An Iranian contact is not automatically an intelligence officer, and a person performing a suspicious task is not necessarily a member of Unit 4000. Counterterrorism must distinguish allegation from attribution, recruitment from operational control, and suspicious behavior from evidence of a terrorist plot.

But the opposite mistake would be equally dangerous: assuming that because an individual is not a trained terrorist, he cannot become part of a terrorist operation.

That assumption belongs to an older era.

The genius-and danger-of this model is its ability to fragment an operation among people who may understand only a fraction of it. One person photographs. Another acquires equipment. Another transfers money. Another provides transportation. Another identifies vulnerabilities. A handler connects the fragments. Only at the upper levels does the entire operational picture become visible.

The structure also contains a weakness. The same handlers required to connect dispersed recruits can become points of exposure. Intelligence shared across Turkey, Cyprus, Azerbaijan and other jurisdictions can allow security services to reconstruct networks from seemingly isolated cases. The material provided on Unit 4000 suggests that the disruption of one operational thread contributed to the exposure of others, revealing vulnerabilities in compartmentalization and command.

That is why the destruction of Unit 4000’s senior leadership should be viewed as a major tactical achievement but not necessarily the end of the threat. Organizations can replace commanders. Tradecraft survives individuals. Recruitment methods can be copied, networks rebuilt, and digital platforms changed.

What cannot easily be restored is secrecy.

The greatest strategic damage inflicted on Unit 4000 may be its exposure.

A clandestine apparatus depends not merely on secrecy but on ambiguity: the ability to separate the local criminal from the Iranian handler, the surveillance assignment from the eventual attack, and the seemingly ordinary online transaction from the state directing it. Once intelligence and law-enforcement agencies understand the architecture, those fragments become easier to connect.

Unit 4000 consequently offers Western counterterrorism agencies a warning that extends far beyond Iran. State-sponsored terrorism is adapting to the digital age. The future operative may not arrive carrying an Iranian passport, receive years of ideological training, or even know at first that he has been recruited by an intelligence service. He may simply receive a Telegram message, complete a small assignment, collect a little cryptocurrency, and accept another task.

The distance between that first payment and an act of espionage or sabotage is precisely the space in which modern counterintelligence must operate.

Iran’s military infrastructure can be bombed. Its commanders can be killed. Its weapons can be intercepted. But the more difficult battlefield is the invisible one: the digital relationship through which a hostile state can turn an ordinary person abroad into a disposable instrument of espionage, sabotage, or terrorism.

Unit 4000 has been exposed. The method it represents, however, has not disappeared.