Iran Conflict: Cyber Threat Activity

Let’s do the thing, shall we?

Questions to consider:

  1. What are the current cyber capabilities of Iran and its proxies?
  2. What are the exigent cyber risks of retaliation in response to the US/Israel attacks?

Most public advisories are vague at best, both on capability and projected action.

Private reports are more detailed, and include both influence operations and some actual attacks by hacktivist groups. Nothing directly attributed to IRGC that has been released AFAICT.

Targeting, such as it is, suggests oil and gas as well as defense-adjacent industries. Historically Iran targets critical infrastructure as well. Wipers are a common tactic.

Please add what you can, with sourcing when possible.

1 Like

One of the primary sources of reports appears to be the “Handala” group, active on X and Telegram (although constantly suspended on the former. They have a LinkTree!

This is an armed conflict, so sometimes things are going to go boom. Consider what compute is in missile/drone range of Iran and proxies that you care about.

1 Like

Kind of regretting having thumbs as I opened this, dropped my phone, and opened the link.

if I get droned, you know what’s up.

More so related to missiles and some of the strategies of Iran, less about cyber and more geopolitical

This attack was attributed to Handala: healthcare in Israel.

Near as I can tell, pretty much all immediate activity is targeted to Israel or in-region allies such as UAE. This could well expand as other regional opponents of Iran join the conflict.

Useful summation for the situation at this point:

Info on US operations prior to the airstrikes. Not much detail, just that it happened.

Also in this report, intel from Jordan that it stopped an attack against its wheat storage systems.

Check Point has a useful profile of some of the usual suspects here:

TL;DR: We’re looking at

  • Influence operations broadly
  • Spearphishing broadly
  • Directed destructive attacks against in-region targets
  • Espionage actions broadly, including detailed impersonation attacks

A nice breakdown of known TAs, including targeting and TTPs:

Beaumont sees nada:

It is interesting that it is in direct contradiction to Stromblad.

As of Q1 2026, following confirmed U.S.-Israeli strikes under Operations Epic Fury and Lion’s Roar, Iranian cyber activity has escalated sharply.

1 Like

I think they are discussing two different kinds of activity. Beaumont focuses on direct action, but what does seem to be increasing is influence operations and phishing/espionage campaigns. Direct action so far appears limited to in-region, mostly targeted at Israel.

2 Likes

Found this buried from a couple days ago. Points to some prior action and emplacement that could be activated.

New attack from Handala:

More on this here from the Irish Examiner:

It is understood that Stryker may have been targeted over business links with Israel, with one worker saying the attack is “very significant”.

“Anything connected to the network is down,” they said.

"All support staff, administrative staff and engineers have been sent home.

“And anyone with Outlook on their personal phones had their phones wiped.”

Zetter with more details.

Looks like Intune might be the wipe vector here.

Guidance from elsewhere that Handala’s TTPs continue to be aligned to this post from 2024 Bad Karma, No Justice: Void Manticore Destructive Activities in Israel - Check Point Research

1 Like

Unit 42 has this new breakdown of Boggy Serpens/MuddyWater TTPs:

https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/

Looks like maybe missile strikes took out a MOIS chief, leader of Handala?

Per reports, at least two Iranians accused of running cyber operations against Western entities were killed in the strikes. One was Mohammad Mehdi Farhadi Ramin, who the Justice Department charged in 2020 with hacking into aerospace and defense companies in America and had been sought by U.S. authorities since then.

The other was Seyed Yahya Hosseiny Panjaki, a deputy minister of intelligence for Israeli affairs at MOIS who is on the FBI Most Wanted list. Cybersecurity sources tell Forbes Panjaki was in charge of the MOIS unit that controlled hacking groups like Handala, long known as a pro-Iranian crew that has successfully targeted Israeli politicians and Western businesses. According to the FBI, Panaki was linked to terror plots and cyberattacks organized by MOIS and and Iran’s Islamic Revolutionary Guard Corps.”

https://www.forbes.com/sites/the-wiretap/2026/03/17/us-strikes-killed-iranian-cyber-chiefs-but-the-hacks-continued/