Iranian cyberattacks have seen rapid and dangerous developments since the military strikes launched by the United States and Israel in late February. These developments have caused a radical shift in the nature of threats, moving from simple disruptive campaigns led by activist hackers to composite, multi-vector threats. These complex operations currently target major financial institutions, aviation sectors, energy industries, and water systems in the Gulf region, the United States, and the European continent, reflecting a strategic shift in deterrence and sabotage methods.
Observers believe this digital escalation comes within the context of attempts to compensate for declining traditional military options, as cyberspace has become the alternative battlefield where severe damage can be inflicted at a lower cost and with limited strategic risk. This shift reflects a growing awareness of the importance of digital infrastructure as a soft underbelly for targeted nations.
Escalation of attacks and the emergence of advanced digital tools
The scale of the new threat is causing genuine shock among digital security experts. Dr. Mohamed Al-Kuwaiti, head of cybersecurity for the UAE government, told Gulf Today that daily cyberattacks on the country’s digital infrastructure have tripled since the conflict began. He explained that these attacks rose from approximately 200,000 to about 600,000 attacks per day. In a related context, Gulf News reported that the true figure could reach up to 700,000 attacks on certain days, varying to include ransomware, data breaches, destructive wiper malware, and website defacement campaigns.
This escalating threat is not limited to the Gulf region alone, but extends to critical targets in Western nations. U.S. intelligence agencies issued an urgent warning this week, noting that Iranian hackers are exploiting vulnerabilities in programmable logic controllers produced by Rockwell Automation. These devices are widely used in critical U.S. infrastructure, including energy and water systems, according to reports published by the Los Angeles Times and Politico.
In a parallel development, researchers at cybersecurity firm Symantec identified activity from the advanced Iranian threat group Seedworm, also known as MuddyWater. The activity of this group was discovered inside the networks of an American bank, an airport, and the Israeli division of an American defense software company, with these breaches dating back to early February. Furthermore, cybersecurity firms revealed that the MuddyWater group is linked to a Russian malware-as-a-service platform operated by a group known as Tag-150, as part of a campaign dubbed “ChainShell.” This campaign uses blockchain-based command and control infrastructure alongside obfuscated malicious payloads, which researchers described as a “generational shift” in destructive capabilities.
Alliance of proxies and sabotage groups
Despite the near-total internet blackout inside Iran following the strikes on February 28, where connectivity levels dropped to between 1 and 4 percent within a few hours according to Palo Alto Networks Unit 42 data, the cyberattack has not slowed down. Approximately 60 threat groups were activated to operate from outside Iran within days, coordinating their efforts under the umbrella of broad sabotage campaigns.
Pro-Russian hackers have formed an alliance with Iran-linked hackers. Specialized initial access brokers have been observed selling stolen credentials to Iran-aligned groups on Russian cybercrime forums. This cooperation among various malicious actors reflects increasing complexity in the cyber landscape.
Extended threat and latent danger
Cybersecurity analysts warn that the most dangerous dimension may lie in what has already been planted inside Western networks. Kindsleys Law firm noted that there are over 60 active threat groups currently being tracked, with 53 of them classified as pro-Iranian. Additionally, an analysis released this month by the Center for Strategic and International Studies warned that Iranian actors, alongside other groups like Volt Typhoon, have pre-positioned malware within the U.S. energy sector, access that the report warned may never be completely eradicated.
Researchers at Thrive NextGen affirmed in a report regarding Seedworm group activity:
“It is near certain that Iranian actors are currently in a state of pre-positioning within critical Western networks.”
Amid the decline of traditional military options available to Tehran, experts emphasize that it will increasingly turn toward exploiting cyberattacks as a primary tool for retaliation and exerting pressure on the international stage.
FAQs
What sectors are targeted in the recent Iranian cyberattacks?
The attacks target major financial institutions, the aviation sector, and energy and water systems in the Gulf region, the United States, and Europe.
How have the capabilities of Iran-linked hackers evolved?
The attacks have shifted from simple disruptive campaigns to complex operations utilizing advanced techniques such as exploiting programmable logic controllers, ransomware, and stealth campaigns, in cooperation with Russian groups.
What is the greatest danger warned of by cybersecurity experts?
The greatest danger lies in the malware already pre-positioned within critical Western infrastructure networks, awaiting activation orders to launch destructive attacks that may be difficult to completely remove.