Private reports are more detailed, and include both influence operations and some actual attacks by hacktivist groups. Nothing directly attributed to IRGC that has been released AFAICT.
Targeting, such as it is, suggests oil and gas as well as defense-adjacent industries. Historically Iran targets critical infrastructure as well. Wipers are a common tactic.
Please add what you can, with sourcing when possible.
One of the primary sources of reports appears to be the “Handala” group, active on X and Telegram (although constantly suspended on the former. They have a LinkTree!
This is an armed conflict, so sometimes things are going to go boom. Consider what compute is in missile/drone range of Iran and proxies that you care about.
This attack was attributed to Handala: healthcare in Israel.
Near as I can tell, pretty much all immediate activity is targeted to Israel or in-region allies such as UAE. This could well expand as other regional opponents of Iran join the conflict.
I think they are discussing two different kinds of activity. Beaumont focuses on direct action, but what does seem to be increasing is influence operations and phishing/espionage campaigns. Direct action so far appears limited to in-region, mostly targeted at Israel.
Looks like maybe missile strikes took out a MOIS chief, leader of Handala?
Per reports, at least two Iranians accused of running cyber operations against Western entities were killed in the strikes. One was Mohammad Mehdi Farhadi Ramin, who the Justice Department charged in 2020 with hacking into aerospace and defense companies in America and had been sought by U.S. authorities since then.
The other was Seyed Yahya Hosseiny Panjaki, a deputy minister of intelligence for Israeli affairs at MOIS who is on the FBI Most Wanted list. Cybersecurity sources tell Forbes Panjaki was in charge of the MOIS unit that controlled hacking groups like Handala, long known as a pro-Iranian crew that has successfully targeted Israeli politicians and Western businesses. According to the FBI, Panaki was linked to terror plots and cyberattacks organized by MOIS and and Iran’s Islamic Revolutionary Guard Corps.”