Breaking Down the Role of Cyber Operations Taken in the Iran Crisis

March 4, 2026, 3:46 p.m.

Description

The report analyzes the cyber aspects of the ongoing conflict between Iran, the US, and Israel. It details a massive cyberattack launched by the US and Israel against Iran, causing widespread internet disruptions and infrastructure failures. The report also covers the activation and retooling of Iranian APT groups for retaliatory operations, targeting critical infrastructure in the US, Israel, and allied countries. Key actors include MuddyWater, Charming Kitten, OilRig, and Elfin. The analysis covers tactics, techniques, and procedures used by these groups, as well as their strategic objectives. The report also discusses the involvement of hacktivist proxies and the victimology of the attacks, affecting multiple countries and industries.

Indicators

  • 1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498

Attack Patterns

  • ZEROCLEAR
  • SHAPESHIFT
  • ZeroCleare - S1151
  • Filerase
  • IOCONTROL
  • Shamoon - S0140
  • Tickler
  • RustyWater
  • GhostFetch
  • Disttrack
  • Multiple Iranian APT groups

Additional Informations

  • Energy
  • Finance
  • Aviation
  • Telecommunications
  • Defense
  • Healthcare
  • Government
  • tylarion867mino.com
  • United Arab Emirates
  • Israel
  • Saudi Arabia
  • Kuwait
  • Jordan
  • United States of America

Linked vulnerabilities