Discussion elsewhere posed this question, and it’s worth some discussion. It also comes at a good moment - I’ve spent the last few weeks deeply entrenched in assessing activity of Iran-aligned threat actors we hear about most, especially Handala and related entities.
This is separate from Iran’s more advanced espionage actors like Muddy Water - they are not covered by the below, and the threat modeling there is more focused.
The thing to understand is that most public Iranian threat actor activity is pretty distinct from most other nation-state actor profiles in that they focus primarily on low-hanging fruit that they can form a narrative around. Technical impact of the compromises takes a backseat to the perception of impact, for a number of reasons - but primarily due to a lack of resources.
Groups like Handala tend to be treated as “aligned” with the regime but acting out of outrage, or resistance against the west, etc. “Handala” itself is a name derived from a Palestian-created symbol; related clusters of activity include “Homeland Justice” or “KarmaBelow80” all also center around justice-related signaling. I am not here to judge any political messages, but what I can speak to pretty well is that this cyberactivist-style framing is almost always a smokescreen for the Iranian Ministry of Intelligence and Security (MOIS).
Think of most Iranian regime-aligned “cyberactivist group” more as a MOIS persona than anything. In that context, their primary goal is not technical impact but influence operations, and they’ve gotten very good at pairing low-to-moderate technical capabilities with well-honed narrative exploitation.
Who can that apply to? Well, pretty much everyone. Healthcare, education, food service. There are so many interconnections across most businesses that a narrative can be spun out of anything, as long as the perception of impact eclipses any other elements in the ensuing reporting and cultural engagement.
Unfortunately, that’s largely what news cycles are incentivized to do now, so it provides keen opportunity for MOIS, right in the sweet spot they seek.
The lesson there largely is, “anyone can be a target - but especially any institution.” However, the way to avoid opportunistic targeting is increasing the cost of compromise. Handala can be patient - they had something like a 14-month dwell time in some Albanian government systems, by some accounts - but by and large they seek less costly opportunities, so every bit of effort on security fundamentals makes you less and less likely to be a sustainable target of opportunity.
We’ve got some research coming out shortly that I’ll add on here when it’s out.
Curious if other folks have thoughts on all this as well.