This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
Dumb for the US: if US were currently MITM with certs copied by its agencies, US won't be able to do that for Iranian / Russian certs.
China and many others run their own CAs, I'd presume Russians could use those if they wanted?