Critical Infrastructure Security, Threat Intelligence, Government security

Cyber operations escalated by Iran following US, Israel attacks

Technology background with national flag of Iran. 3D rendering

Multiple cyberespionage campaigns and distributed denial-of-service intrusions have been deployed by Iranian hackers against Israel and Persian Gulf countries following the joint U.S.-Israeli missile strikes against the country over the weekend, with threat intelligence analysts warning of imminent cyberattacks aimed at U.S. organizations, The Register reports.

Approov observed that Iran's reconnaissance efforts commenced weeks before the joint military strikes, with the country conducting significantly more API and mobile app probing attacks beginning in early February. Malware staging for intrusions against Israel and the Middle East ahead of the strikes was also noticed by Binary Defense Director of Threat Intelligence JP Castellanos, who said that various pro-Iran hacking groups have since targeted industrial control systems in Israel, Jordan, Turkey, and other Gulf countries.

On the other hand, Check Point Research analysts reported that Iranian state-backed threat operation Cotton Sandstorm, also known as Haywire Kitten, had its Altoufan Team persona reemerge to target Bahrain-based organizations. Cotton Sandstorm was also noted by Check Point to have launched spear-phishing campaigns delivering the WezRat information-stealing malware months before the U.S.-Israel attack, with certain intrusions also involving the WhiteLock ransomware.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds