Iran — Cyber Threat Profile
Iran's cyber posture was reshaped by the February-April 2026 war with Israel and the United States, when coordinated cyber and kinetic strikes disrupted Iranian communications and cut national internet connectivity to roughly 1-4% for over 60 hours. Iran-aligned hacktivist groups and state-linked proxies have since been linked to retaliatory DDoS, defacement and infrastructure-probing campaigns against US and allied targets into mid-2026. This follows a June 2025 campaign by the Israel-linked Predatory Sparrow group, which struck Bank Sepah and the Nobitex exchange, destroying roughly 90 million dollars in crypto assets. Domestically, Tehran continues extensive internet filtering, including a nationwide blackout beginning 8 January 2026.- National CERT/CSIRT: Iran National CERT Coordination Center (MAHER)
- World Cybercrime Index 2024 (origin significance): 4.78 / 100, #11 worldwide
- Secure Internet servers per 1M people (2024): 7,225.7 (source: World Bank)
- Internet users (2024): 85.3% of population (source: World Bank)
Latest Iran coverage
- Iran ramps up dissident surveillance with fake VPN and media apps 2026-07-01 · Nation-State
- From Hacktivist to State Proxy: How Handala Became Iran's Most Prominent Cyber Persona 2026-03-03 · Nation-State
- Operation Olalampo: MuddyWater Deploys Rust CHAR Backdoor, GhostFetch/GhostBackDoor, and Telegram Bot C2 Against MENA Organizations 2026-02-20 · Nation-State
- DHCSpy Android Spyware: MuddyWater's VPN-Masquerading Surveillance Tool Active Since August 2022 Targets WhatsApp, Contacts, and Media 2026-02-16 · Nation-State
- MuddyWater Targets CFOs Globally with Firebase CAPTCHA Phishing, NetBird Abuse, and Hidden Admin Account Persistence 2026-02-16 · Nation-State
- IRGC-Affiliated CyberAv3ngers Target Unitronics PLCs in Water, Energy, and Healthcare Sectors Across Multiple Countries 2026-02-16 · Nation-State
- MuddyWater Replaces Atera RMM with Custom MuddyRot C Implant: PDF-to-Egnyte Delivery, COM-Based Scheduled Task Persistence, and Raw TCP C2 2026-02-16 · Nation-State
- MuddyWater Deploys BugSleep Backdoor Against Israeli Municipalities, Airlines, and Media: Active Development with EDR Evasion via ProcessSignaturePolicy 2026-02-16 · Nation-State
- OilRig Outer Space and Juicy Mix Campaigns: Solar and Mango C#/.NET Backdoors Target Israeli Organizations with XOR Encryption, Compromised Israeli Websites as C2 2026-02-16 · Nation-State
- Abraham's Ax Linked to Moses Staff: COBALT SAPLING Operates Dual Hacktivist Personas Targeting Israel and Saudi Arabia 2026-02-16 · Nation-State
- APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents 2026-02-16 · Nation-State
- APT35 Infrastructure Analysis Exposes Phishing Campaign Targeting Egyptian Shipping and Israeli Pipeline Interests 2026-02-16 · Nation-State
- MuddyWater Targets Turkish and Pakistani Organizations with Canary Token Anti-Analysis, PDF Lures, and PowerShell Downloaders 2026-02-16 · Nation-State
- APT33: Iran's IRGC-Linked Espionage Group Targets Aviation, Energy, and Defense Across Three Continents 2026-02-16 · Nation-State
- MosesStaff Technical Analysis: PyDCrypt Loader and DCSrv Wiper Use DiskCryptor for Ideologically Motivated Destruction Without Ransom 2026-02-16 · Nation-State
Threat actors targeting Iran
Most targeted sectors
Recent claimed incidents
Read the full analysis on IntelFusions