Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware.
Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were sent. Kaspersky’s research documented two previously undocumented malware families from the APT group, delivered through fake coding challenges sent to job seekers on LinkedIn.
The setup is almost embarrassingly simple once you see it laid out. A fake recruiter contacts a software engineer, offers a role, and sends a coding assessment hosted on a completely legitimate-looking Amazon S3 link, the kind of hosting nobody would think twice about.
“During recent threat research, we detected suspicious activity on a system in Afghanistan. We traced it to an archive containing a software development project that the user may have received during a job application process.” reads the report published by Kaspersky. “The archive purported to contain a coding challenge for candidates applying for an engineering role.”
The archive includes a README with a three-hour time limit and an explicit rule against using AI assistants, which sounds like a normal anti-cheating measure until you realize what it’s actually preventing.
Kaspersky spells out exactly why that rule exists.
“The README also imposed a three-hour time limit and prohibited the use of AI assistants.”states the report. “Notably, an AI code-review assistant tasked with auditing the project would likely have flagged the suspicious first-line import of an unknown npm package and warned the targeted developer that the project was trojanized.”
the researchers write, which means the “no AI” instruction isn’t about fairness in a coding test at all, it’s a deliberate move to stop the one tool most likely to catch the malware before it runs.
The first malware family, called NodeRabbit, is written entirely in Node.js and can run on Windows, Linux, and macOS from the same codebase. That’s a change for Mirage Kitten, which has traditionally used malware written in C, C++ and Go.
NodeRabbit is hidden inside a fake npm package included in the coding test rather than published online. Once the victim runs it, the malware starts a background process and connects to infrastructure hosted on Azure, using AES-256-GCM encryption to protect its communications.
Newer versions added checks to detect sandboxes and analysis environments. The malware looks at system memory, the number of CPU cores and how long the machine has been running before deciding whether to continue.
One sample found in Egypt takes that trick a step further. When NodeRabbit suspects it’s being analyzed, it first sends a few harmless requests to Google, Microsoft and Cloudflare, then stops without contacting its real command server. That helps its traffic look like normal background activity instead of an obvious connection to the attackers.
A third variant, found on a system in Ethiopia, expanded the malware’s command set from 11 to 23 and added something genuinely unusual: the ability to plant a fake VS Code extension disguised as “GitHub Copilot Helper,” complete with a stolen publisher name to look legitimate, plus a technique that quietly injects a malicious launcher into a Git repository’s hooks so the malware relaunches every time someone merges or checks out code.
The second malware family, PollCat, takes a stranger route to establish itself. It’s disguised as a React coding challenge that requires entering a six-digit access code supposedly provided by the recruiter, with a ticking countdown designed to pressure the victim into working fast without scrutinizing anything.
“While tracking NodeRabbit infections, we discovered another malicious tool we dubbed PollCat, which is also distributed under the guise of a programming challenge. The sample we obtained resides inside RankChallenge-react, a React code-fixing challenge presented as a time-limited developer assessment. Running the project invokes npm i && node index.js, which starts the local application and attempts to open the challenge in the user’s browser.” states the report. “
What victims don’t realize is that PollCat starts running and begins talking to its command server the moment the application loads, well before anyone types in that access code at all.
Kaspersky linked both malware families to Mirage Kitten with high confidence. Researchers compared PollCat’s network code with an older backdoor called Retrograde, also known as MiniFast, and found that the two use almost the same connection process.
One detail is especially telling: both malware families treat an HTTP 400 error as a successful registration and extract a session token from the response. That unusual behavior is unlikely to appear by chance in two unrelated malware families.
Victims identified so far cluster in fintech and aviation organizations across Egypt, Ethiopia, and Afghanistan, consistent with Mirage Kitten’s long-standing focus on the Middle East and Africa. If your organization does any hiring through LinkedIn outreach involving take-home coding assessments, this is worth flagging to your engineering team directly, because the lure here isn’t a suspicious email with bad grammar, it’s a completely normal-looking job opportunity with a legitimate cloud-hosted download link and a plausible-sounding reason not to use the one tool that would have caught it.
“Mirage Kitten’s latest activity marks a notable evolution in the group’s tooling: NodeRabbit and PollCat are the group’s first Node.js/JavaScript-based implants, departing from its usual native malware deployed through DLL search-order hijacking.” concludes the report.
“The delivery mechanism, however, remains consistent with Mirage Kitten’s historical tradecraft: the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyberespionage purposes. We continue to track the group’s activity and will report on new developments in future publications.”
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at home.
Read more in my article on the Hot for Security blog.
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states.
Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy infrastructure.
“Iran shut down a British power plant for four days in an unprecedented cyber attack, The Telegraph can disclose.” reads the report published by The Telegraph. “It is thought to be the first time that hackers affiliated to the Iranian regime have succeeded in closing down such a facility in the UK, and is believed to be the most successful cyber attack of its kind.”
British officials did not name the power plant because of security concerns. Staff worked for four days to restore it, but the plant was small and the outage did not affect the UK’s wider power supply. Still, the government warned power companies and businesses about the incident and provided guidance on how to respond.
The attack was reported to the National Cyber Security Centre (NCSC), part of GCHQ, which helps protect the UK’s critical infrastructure. The NCSC did not comment on the specific incident.
The US water infrastructure attacks hit dozens of wastewater treatment plants across 12 states, causing flooding and loss of pressure from taps. Authorities in affected areas told customers to boil water. The first reports came from Minnesota on July 26, followed by similar breaches in Michigan, Georgia, South Dakota, and New Jersey. The FBI attributed those incidents to “malicious cyber actors”; US government sources later confirmed the threat most likely originated in Tehran.
The UK attack is not thought to have been designed to harm civilians. The more probable intent was to demonstrate that hackers linked to Iran’s Islamic Revolutionary Guard Corps could gain access to UK infrastructure and shut it down at will. A four-day outage at a small generator that nobody outside the industry noticed is, from that perspective, a successful proof of concept.
Iran has accelerated its cyberattacks on Western countries since the US and Israel began air strikes in February. Suspected Iranian operations have been reported in Germany, Poland, Finland, Belgium, and Albania, with Israel and other Middle Eastern countries remaining the most frequent targets. In March, the NCSC advised British organisations to review their security posture in light of the wider conflict. NCSC chief executive Richard Horne said in June that the agency had handled more than 200 attacks on critical national infrastructure in the previous year alone.
The timing is awkward for the intelligence and security committee, which oversees UK spying agencies.
“Experts have long warned that the UK is unprepared for the scale of the threat of malicious cyber attacks from foreign adversaries, and the intelligence and security committee, which oversees spying agencies, reported last year that the chance of an Iranian cyber attack on British infrastructure was “unlikely”.” continues the report.
A Cabinet Office risk assessment published last month placed the probability of a serious and successful cyberattack on domestic infrastructure at between five and twenty-five percent. The same document warned that AI is making attacks faster and cheaper to run, and is lowering the technical bar for anyone wanting to attempt them.
The government’s public response leaned hard on the size of the target. A government source told The Telegraph: “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near. It’s a very small-scale site, less than a rounding error compared to grid capacity.”
A government spokesman said the UK has a strong and resilient energy system and that the incident never threatened the wider power network. While both statements are technically true, they do not answer a key question: should it be considered acceptable for even a small power plant to remain offline for four days?
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide.
Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, an Iran-based operation running hacking campaigns since at least 2013 on behalf of Iran’s Islamic Revolutionary Guard Corps and other government and university clients.
According to DoJ, the group compromised systems at 144 US universities and 178 foreign ones, plus at least 42 US private companies, 11 foreign companies, five federal and state government agencies, and two nongovernmental organizations. They pulled more than 31 terabytes of academic data and intellectual property out of those systems, along with entire employee email inboxes wherever they had access.
“The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs.” reads the press release published by DoJ. “The defendants conducted many of these intrusions on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), one of several entities within the government of Iran responsible for gathering intelligence, as well as other Iranian government and university clients. Nine of the 17 defendants charged in the S2 indictment were previously charged in a 7-count indictment announced in March 2018. The case is assigned to U.S. District Judge Jesse M. Furman.”
The hackers targeted more than 100,000 professor accounts worldwide and broke into about 8,000 of them in around 24 countries. They used stolen credentials to access research papers, theses, dissertations and academic journals, which were then sold online.
The stolen material was offered through websites such as Megapaper.ir and Gigapaper.ir. Customers could buy academic resources or use compromised professor accounts to access university libraries. The operation turned stolen academic credentials and research into a profitable business.
One name on the new charge sheet connects this case to something much more publicly memorable. Behzad Mesri, listed among the newly added defendants, was separately charged years ago with breaking into HBO’s systems, stealing proprietary data, and attempting to extort the company for roughly $6 million in Bitcoin. This indictment ties him and four co-defendants to that same intrusion as part of the broader Mabna Institute operation, connecting a headline-grabbing entertainment industry hack to a much larger state-linked espionage campaign.
The financial damage extends well beyond stolen research. According to the indictment, other defendants ran password spray attacks against private companies and at least two government entities, causing victims to spend more than $20 million investigating and cleaning up after the intrusions.
““Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” said U.S. Attorney Jamie McDonald for the Southern District of New York. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad. Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength. This office and our partners will continue to protect American innovation and pursue accountability for the individuals behind these attacks.””
Five of the newly charged defendants, Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh, now carry a combined bounty attached to their names. The State Department’s Rewards for Justice program is offering up to $10 million for information leading to their location, funneled through a Tor-based tip line for anyone willing to share what they know. Given that most of these defendants are almost certainly still in Iran and unlikely to face a US courtroom anytime soon, that reward is really the only lever prosecutors currently have.
An indictment isn’t a conviction, and every defendant here remains legally presumed innocent unless proven otherwise in court. But the FBI’s own framing of the case makes the intended message pretty clear regardless of what happens next: eight years between the original charges and this expanded version isn’t hesitation, it’s the department demonstrating that an open case file doesn’t have an expiration date, even when the people on it never set foot on American soil.
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption.
The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to at least 12 states since late July. The attacks are linked to Iranian hackers targeting industrial control systems made by Rockwell Automation and potentially other major vendors. Minnesota was the first to confirm over 30 affected water systems, followed by Michigan, South Dakota, and Georgia, and now two more states.
“The City of Cape May Sewer Department and the Borough of Woodbine Water Department reported the attacks on Thursday. Officials said the attacks happened nearly simultaneously early in the morning on July 27.” reports Fox29 “Both systems were impacted for approximately 12 hours.”
Water kept running in both New Jersey districts throughout the incident, and tests afterward confirmed no impact on water quality or safety. Cape May city manager Paul Dietrich told Fox29 that hackers changed settings to prevent remote access to the system, but did not take control of the systems to do anything — which is a meaningful distinction, and not the kind anyone wants to be making about their water supply.
“Cybersecurity experts say hackers could control a lot after breaking into a local water system. ‘They’re actually having the ability to control the water pressure, meaning that they could increase the pressure and cause flooding, or they could decrease the pressure so that you would have a reduced pressure, or ultimately, have no water flow at all,’ said Ian Marlow, CEO of FITECH.” continues Fox29.
In Alabama, the Childersburg Water, Sewer and Gas system was hit the same day, July 27, with hackers targeting industrial control systems. The attack didn’t disrupt water services there either. Neither department’s customer data was accessed in New Jersey, and no significant service disruption was reported in Alabama.
“The Childersburg Water, Sewer, and Gas Board reported that its computerized monitoring and control network was targeted in a cyberattack late last month, prompting officials to temporarily disconnect the system while additional safeguards are put in place.” reports Sylacauga News. “According to the utility, the incident occurred on Monday, July 27 and involved a programmable logic controller, a type of industrial device used to help manage utility operations. Officials said the attack was part of a broader effort that also targeted several other public utilities.”
The pattern across all confirmed states is consistent: attacks targeted operational technology and industrial control systems, some facilities shut down systems as a precaution, disruptions were limited, and drinking water remained safe in every case. The FBI confirmed at least seven states had been targeted as of July 30. Wisconsin, Pennsylvania, and Washington have issued warnings to water utilities without confirming attacks. New York has not said whether its utilities were hit but announced more than $9 million in grants to strengthen water sector cybersecurity.
The practical lesson from every confirmed case so far is the same one CISA has been repeating since its July 30 alert: get PLCs and industrial control systems off direct internet exposure, because the attackers are scanning for exactly that exposure and finding it.
And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.
“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
No word on whether he believes the other six states have hacked themselves as well.
US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption.
Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not just looking around. They’re changing things.
The updated advisory from CISA, the FBI, NSA, and the Department of Energy says these actors are getting into programmable logic controllers, the small industrial computers that run pumps, valves, and safety alarms. Once inside, they can mess with what operators see on their screens. That’s how you get outages nobody saw coming.
“The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs).” reads the advisory. “These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.”
This isn’t new territory. Back in April, the same agencies flagged Iranian hackers going after Rockwell Automation controllers specifically. The updated advisory widens the net. Now Schneider Electric and Siemens equipment is on the list too.
US agencies have expanded guidance on detecting malicious code changes in PLCs after observing attacks targeting Rockwell Automation, Schneider Electric, Siemens, and other internet-exposed industrial controllers.
Attackers access exposed devices via OT ports (44818, 2222, 102, 502) and modems over SSH (port 22), then exfiltrate PLC project files using vendor tools such as Studio 5000, EcoStruxure Control Expert, and TIA Portal. They modify or delete project logic, including Add-On Instructions (AOIs), manipulate HMI and SCADA displays, and disable shutdown and alarm functions, allowing industrial systems to enter unsafe states without alerting operators.
Organizations should follow vendor security best practices, remove PLCs from direct internet access using secure gateways and firewalls, and monitor logs for indicators of compromise and suspicious traffic on OT ports such as 44818, 2222, 102, and 502. Rockwell users should set controllers to Run mode, while suspected victims should contact vendors and federal agencies.
The agencies say potentially any internet-exposed industrial control system could be a target. Here’s the part that should make plant operators lose some sleep. In one case, the hackers didn’t just peek at a system. They rewrote the controller’s programming logic to disable the processes meant to trigger shutdowns and alarms during dangerous conditions.
“At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.
“Since at least March 2026, the authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT group disrupted the function of PLCs.” states the advisory. “Organizations across several U.S. critical infrastructure sectors (including Government Services and Facilities, WWS, and Energy Sectors) deployed these PLCs within a wide variety of industrial automation processes. Some of the victims experienced operational disruption and financial loss.”
Systems could then drift into unsafe territory with nobody watching the warning lights, because the warning lights had been switched off from the inside.
“After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays [T1565].” continues the advisory.” Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.”
The advisory ties the activity to the ongoing conflict between Iran and the US and Israel, framing it as an effort to cause disruption inside the United States. It fits a pattern going back to February, when the war started and Iranian-linked hacking picked up sharply across the region.
Not all of it looks like this. Some of it has been standard espionage and embarrassment campaigns, like the leak of FBI Director Kash Patel’s personal email account. Some of it has been genuinely destructive. The Iranian group known as Handala remotely wiped tens of thousands of employee devices at medical device maker Stryker, and separately claimed a breach at California’s Cal Water, saying it could disrupt the water supply. Cal Water pushed back, saying it found no sign anyone had touched its operational networks.
That’s the pattern worth watching: espionage on one track, disruption on another, and now a wider set of manufacturers exposed on the operational technology side. If your PLC talks to the internet, it’s not a bystander anymore.
Nobody wants their water plant’s alarm system to be the one thing an adversary quietly switches off. Time to check who can actually reach those controllers from outside.
In April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.
Executive Summary
The cyber risk remains quieter than the public narrative. It rests on persistent access, trusted administration, service-provider pathways, selective disruption, and personas that magnify technical effects.
Iran-linked activity is not a single threat set. MOIS, the IRGC Intelligence Organization, the IRGC Cyber-Electronic Command, personas, surveillance operators, and opportunists pursue distinct missions.
The principal strategic risk is access optionality. The same compromised account, service provider, or remote-management foothold can support intelligence collection, downstream targeting, or selective disruption as tasking changes.
MOIS-linked personas such as Handala, Homeland Justice, and Karma combine intrusion, destruction, disclosure, and coercion. Their impact claims frequently outpace independently verified evidence.
OT risk remains exposure-driven. Internet-facing PLCs, weak credentials, and poor remote-access governance have enabled real disruption, but interface access alone does not demonstrate process manipulation or physical effect.
Inside Iran, shared-service concentration, connectivity controls, and limited disclosure obscure the incident picture. External operations, domestic control, and resilience failures intersect there.
A Working Taxonomy
“Iran-linked” is a broad analytic descriptor, not a single actor or command structure. Iran’s cyber ecosystem spans operators tied to the Ministry of Intelligence and Security (MOIS), the IRGC Intelligence Organization, and the IRGC Cyber-Electronic Command, plus state-aligned collectives, domestic-surveillance clusters, and opportunists. These entities differ in command relationships, missions, targeting, tradecraft, and risk tolerance.
Public naming adds complexity. Vendors assign different labels to overlapping activity sets, and some names refer to actor clusters while others describe campaigns, personas, malware families, or infrastructure.
We offer the following as a working crosswalk, rather than a claim that every label is a one-to-one alias, that every organizational relationship is proven, or that the picture is static.
IRGC-IO-linked high-trust social engineering and cloud collection
Cavern Manticore
Espionage via service-provider and RMM pathways; MOIS link at moderate confidence, single-vendor reporting
TAG-182. Related, but not aliases: Ferocious Kitten; Domestic Kitten/GreenEcho; Rampant Kitten
Surveillance of dissidents and diaspora; no sponsor publicly attributed with confidence
CyberAv3ngers / Storm-0784 / CL-STA-1128
IRGC-CEC-affiliated opportunistic OT targeting
Predatory Sparrow / Gonjeshke Darande
Comparison case only: destructive anti-Iran operations, widely reported as Israel-linked
We base our distinction on mission rather than branding. In practice, we can identify several recurring mission sets:
persistent espionage and access enablement;
destructive, coercive, and influence operations through public personas;
high-trust social engineering and cloud compromise;
surveillance of dissidents and civil society; and
opportunistic targeting of operational technology.
These categories overlap, but they offer a more reliable basis than actor names for assessing intent and prioritizing defenses.
1. The Durable Threat Is Access Optionality
Three months of headlines have tracked leaks, defacements, and outages. However, there is a quieter accumulation of access that matters more, where a foothold gained for collection today can be converted to disruption tomorrow or whenever tasking changes.
For example, activity attributed to the MOIS-linked Seedworm/MuddyWater cluster began in early February, before the opening strikes. Affected environments included a U.S. bank, a U.S. airport, nonprofits, and the Israeli operation of a U.S. software supplier serving defense and aerospace customers. Researchers identified multiple backdoors and an attempted transfer of data to commercial cloud storage.
Because that activity preceded the kinetic campaign, it is tempting to call every intrusion wartime pre-positioning. In practice, the evidence supports a narrower reading. We might know access was gained before the strategic picture changed, but that doesn’t tell us what the compromise was originally for. A compromised supplier may expose customer identities and trusted administrative paths, but it’s only a software supply-chain compromise if there is evidence that downstream customers, builds, updates, or distribution were affected. What matters is that the operator had options once the conflict escalated.
A similar timing pattern appears in Screening Serpens. Unit 42 identified six new RAT variants deployed between February and April against apparent targets in the United States, Israel, the UAE, and the wider Middle East. The campaigns continued the actor’s tailored recruitment lures while adding AppDomainManager hijacking, and the conflict appears to have increased tempo without creating the espionage mission.
This is also why high-trust people are part of the enterprise perimeter. Long-running APT42 operations have targeted journalists, researchers, NGOs, academics, activists, and government-linked individuals. One compromised cloud account holds organizational context, relationships, and internal deliberations, and can yield collection, impersonation, lateral targeting, and entry into the wider organization.
Third party reporting extends that logic to service providers. Check Point’s July reporting on Cavern Manticore described intrusions in which existing RMM access and compromised IT-provider environments opened paths into targets. Check Point assesses an MOIS relationship based on technical and operational overlap with MuddyWater and Lyceum; public corroboration remains limited, so the mapping should remain moderate-confidence.
SysAid itself was not compromised, and no SysAid vulnerability was involved. The actor already had access and abused a legitimate deployment feature, and in many intrusions the weakness is the authority already granted to an administrator, service account, RMM agent, identity provider, or support organization rather than the product itself.
The war has also not displaced Iran’s standing regional requirements. Previously documented APT34 activity against Iraqi government infrastructure shows a durable mission of collecting political, diplomatic, and telecommunications intelligence from neighboring states. Iraq and the Gulf are not peripheral theaters simply because the visible strikes occur elsewhere.
Our assessment is that Iran’s most valuable cyber asset is optionality. Persistent access can support immediate collection, future tasking, transfer to another operational element, or disruption when political value exceeds operational cost.
At least one recent Handala wiping script was assessed as likely AI-assisted, and Iranian operators are likely using generative systems to accelerate coding, translation, lure development, and impersonation. The evidence supports an efficiency multiplier rather than a separate mission set.
2. Persona Operations Are Operational Infrastructure
Iran-linked intrusions are often claimed in public by personas with hacktivist-style brand names like Handala Hack Team or Homeland Justice. We observe that these personas provide threat actors with more than just post-intrusion propaganda. They serve as reusable operational infrastructure, supporting attribution masking, coercion, disclosure, intimidation, and amplifying claims.
A meaningful portion of higher-impact public activity resolves to personas of the MOIS-linked Void Manticore apparatus. In March, the U.S. Department of Justice seized four domains associated with Handala, Homeland Justice, KarmaBelow80, and a related “Red Wanted” operation, identifying shared leak infrastructure, Iranian IP ranges, and a common playbook combining destructive intrusions with data publication, doxxing, and threats.
Still from Handala’s ‘Red Wanted” propaganda video release
That evidence supports treating Handala Hack Team, Homeland Justice, and Karma as related fronts within a common MOIS-linked system, and Check Point has also documented collaboration involving Scarred Manticore. Treating the personas as interchangeable aliases in a strict CTI sense goes further than the evidence allows. Personas can serve different geographic, linguistic, or operational purposes, and the same apparatus may retire, merge, or repurpose brands as requirements change.
It is worth noting that following the March 2026 infrastructure seizure(s), Both Handala and Homeland Justice personas have continued to establish new infrastructure, and communications channels for influence and narrative control purposes. Handala, in particular, has been consistent with regards to communication over the observed timeline.
A more defensible model has three layers:
State-managed persona systems combine intrusion, destructive effects, data theft, leaks, threats, and messaging under deniable brands.
Ideologically aligned networks may coordinate targets, amplify claims, or share stolen material without evidence of direct tasking.
Opportunists and service sellers enter for attention, access sales, or revenue, relying on DDoS-for-hire, recycled data, and low-impact defacement.
These layers interact. An opportunist may sell access to a state operator, and a persona may amplify a third party’s claim, none of which proves shared organization. Treating direction, alignment, collaboration, brokerage, and amplification as synonyms inflates actor counts and obscures the operators with real access.
The March attack on Stryker is the clearest public case for this layer. Stryker confirmed global disruption to its Microsoft environment affecting ordering, manufacturing, and shipping. Early statements said no malware had been detected; a later update clarified that the actor used a malicious file to execute commands and conceal activity, though the file could not spread inside or outside Stryker’s environment.
Handala claimed responsibility, and the Justice Department later stated an MOIS-controlled Handala domain was used to claim the March 11 destructive attack. Stryker did not attribute the incident to Handala or validate the actor’s quantitative claims of device destruction and data loss. Those remain actor assertions rather than confirmed findings.
Handala’s original Wiper claim against Stryker
The public claim is part of the operation. Victim lists, leak samples, countdowns, doxxing, and unverifiable impact figures impose reputational and psychological costs before technical scoping is complete. These are all fundamental steps in the personas’ playbook to help craft and control the narrative and potentially sway the sentiment of the public. In a persona-led incident, publication and personal targeting may begin while responders are still establishing blast radius.
3. OT Risk Is Real, and Evidence Quality Matters
The strongest public evidence of wartime Iran-linked activity against U.S. operational technology is the April 7 joint advisory on internet-facing Rockwell Automation and Allen-Bradley PLCs, documenting activity against government facilities, water and wastewater organizations, and energy environments, in several cases with operational disruption and financial loss.
Two U.S. cases show why cyber-physical reporting needs exact boundaries. On April 7, CISA, the FBI, NSA, EPA, Energy Department, and U.S. Cyber Command warned that Iran-affiliated actors were exploiting internet-facing Rockwell Automation/Allen-Bradley programmable logic controllers. The agencies reported manipulation of project files and HMI/SCADA displays, operational disruption, and financial loss across multiple critical-infrastructure sectors. That is a confirmed cyber-physical campaign described by multiple government agencies.
The June California Water Service case is narrower. Handala claimed that it had hacked the utility and could have interrupted water service. Analysis of the actor’s published material supported access to customer billing data and an internal RTKBase/NTRIP GPS-correction environment used by field crews. Cal Water said it was investigating and that preliminary findings showed no known operational disruption to water, wastewater, or billing. The supported finding is potentially significant IT and field-support-system access—not demonstrated control of treatment, chemical dosing, or water distribution.
We should be cautious about attribution. The advisory described Iranian-affiliated cyber actors and referenced earlier IRGC Cyber-Electronic Command activity associated with CyberAv3ngers. Separately, Unit 42 maps the cluster it tracks as CL-STA-1128 to CyberAv3ngers and Microsoft’s Storm-0784 label. Those assessments are compatible, but they do not prove that every exposed PLC or claimed compromise involved the same operator.
Pro-Iran channels keep publishing images and videos appearing to show access to HMIs, SCADA interfaces, and industrial engineering software. Some may be genuine unauthorized access, but others may not. Analysts should apply an evidence ladder, in which each rung requires evidence beyond the one before it.
Provenance and target validation: Can the organization, system, location, and timeframe be independently established?
Interface visibility: Can the actor display a login page, dashboard, or management interface?
Authenticated interaction: Can the actor navigate the live interface or query current values?
Write or control capability: Can the actor change a setting, logic file, operating mode, or command value?
Process effect: Did the change alter an operational process outside the interface?
Physical or safety consequence: Did the process change produce a verified real-world outcome?
Stronger claims need logs, process data, engineering review, operator testimony, timestamps, configuration evidence, or independent confirmation of the outcome. These personas will falsify or embellish claims at times for various reasons. It is crucial that we scrutinize claims for validity, accuracy and technical viability.
Regardless of which actor is behind any given incident, the attack surface is well-documented: Internet-facing PLCs, unmanaged HMIs, remote engineering services, default credentials, permissive vendor access, and poorly segmented management networks. Any of these can create opportunities for meaningful disruption. In some environments, what separates a low-skill intrusion from a serious incident is the authority exposed to the internet rather than attacker capability.
Evidence quality should determine how an incident is described, not whether an exposed control path is closed.
4. Inside Iran | Concentration Risk, Underreporting, and Surveillance
Iran is also on the receiving end of this conflict, and the picture inside the country is shaped by more than just foreign intrusions. Shared-service concentration, connectivity controls, domestic surveillance, and weak disclosure increase both operational risk and analytic uncertainty.
Banking: The Dependency Is The Strategic Finding
In this context, Iran has experienced at least two officially reported banking disruptions this past June, but public record does not establish these as a one continuous intrusion.
On June 14, Iranian authorities reported that an attack on shared communications infrastructure disrupted services at four banks: Bank Melli, Bank Tejarat, Bank Saderat, and the Export Development Bank of Iran, with no unauthorized access to or deletion of customer data identified. A second reported attack on June 23 disrupted card services at three of the same banks, affecting ATMs, point-of-sale terminals, and mobile applications. These overlaps are notable, but timing and claims alone are not enough to prove a coordinated, multi-stage campaign by any one specific actor.
Affected ATM, Bank Tejarat
The incidents remain publicly unattributed. Predatory Sparrow is an obvious comparison given prior high-impact operations against Iranian financial targets, but on the available evidence it is not an attribution. The June incidents lacked the public claim, evidence package, and established destructive signature of the group’s better-known operations.
The strongest conclusion is architectural rather than actor-centric. Failure of a shared communications provider, card platform, identity service, or recovery environment can propagate across institutions and become a national public-confidence event, with outage scale reflecting dependency concentration as much as attacker sophistication.
Fallback systems belong to the same risk model, and the lesson is not confined to Iran. A recovery platform is more than an emergency copy of production. Isolation, capacity, data currency, and administrative security determine whether it operates safely under pressure, and a fallback sharing credentials, management tooling, or upstream providers with production may reproduce the failure when needed most.
Surveillance Infrastructure Can Become Targeting Infrastructure
Iran’s surveillance and communications systems are not separate from the conflict. Associated Press reporting, based on intelligence and operational sources, described Israeli access to Iranian surveillance-camera networks supporting the tracking of senior leadership; absent disclosed access paths or technical artifacts, those details should remain described as reported rather than confirmed.
The structural risk outlasts any single account. Camera networks, subscriber records, location histories, and identity databases concentrate information about people and movement, and infrastructure built to monitor a population can become targeting infrastructure for a foreign service.
The relationship also runs in reverse. Disrupting the same communications layer degrades public warning, incident response, and independent reporting, making it a surveillance asset, an intelligence target, a resilience dependency, and a domestic-control mechanism at once.
Public Reporting Is A Floor, Not A Denominator
Banks are the best-documented internal target set in the public record reviewed here, and not necessarily the only one. Incidents affecting telecommunications, energy, or military-adjacent environments may be underrepresented, a collection hypothesis rather than a confirmed count. Iranian reporting is constrained and fragmented, and incidents may be kept private or described too vaguely to distinguish attack from technical failure. The public incident set is a floor, evidence that at least those events occurred rather than a denominator for total activity.
The same logic cuts the other way, though. Knowing that incidents go unreported is not a license to fill the record with rumor, and however many compromises are plausibly hidden inside Iran, they cannot be used to attribute a specific outage, validate an actor’s claim, or turn an unexplained failure into evidence of cyberattack. When collection is thin, the honest answer is explicit uncertainty rather than false precision.
The Blackout Is Both A Collection Gap And An Attack Surface
Iran began restoring international connectivity after an 88-day shutdown, but the return was partial and uneven. A 2026 technical paper found that forwarding-plane null-routing could leave BGP announcements apparently stable, causing route-based monitors to understate the scale of disconnection.
For CTI, telemetry loss is not uniform. External visibility falls while selected domestic services stay reachable, so apparent recovery in one dataset may reflect exemptions or measurement artifacts. The blackout is also not an all-purpose causal explanation. Public evidence does not establish that connectivity restrictions caused the banking compromises or enabled a specific intrusion. Its defensible effects are on visibility, coordination, validation, and trust.
Those effects create a secondary attack surface. Users seeking secure communications or ordinary services turn to VPNs, media players, and utilities from informal channels, and recent TAG-182 activity used exactly such lures to distribute MarkiRAT to Farsi-speaking users inside and outside Iran. Iranian surveillance operators can exploit attempts to bypass connectivity restrictions, while foreign intelligence services and criminals can exploit the same demand, putting journalists, NGOs, diaspora communities, and Iran-exposed employees at risk from several directions.
Our assessment is that the internal Iranian cyber environment is defined by three overlapping risks:
attack against national and institutional infrastructure;
concentration of critical services and recovery dependencies; and
surveillance of people attempting to operate through the resulting disruption.
Treating only the first as “cyberwar” misses a substantial part of the operational reality.
Defender Priorities
For enterprise defenders, the central question extends beyond who is attacking now. It includes which access predates escalation, which trusted paths remain, and what an operator could do with them under different tasking. Review identity, cloud, RMM, and service-provider relationships against that standard, and map shared dependencies: which nominally separate services would fail together, and which recovery paths rely on the same identity provider, carrier, or administrator as production.
For incident responders, persona-led operations weaponize uncertainty. Publication, doxxing, and direct approaches to employees may begin before scoping is complete, so technical response, legal review, communications, and physical-safety support cannot operate sequentially.
For OT operators, the priorities remain clear: remove direct internet exposure; place remote access behind authenticated gateways with phishing-resistant MFA; restrict programming-mode and logic changes; enforce source and time restrictions on vendor access; monitor engineering workstations and industrial protocols; preserve offline project files and known-good configurations; and verify that recovery does not depend on the same identity, virtualization, or management environment that may have been compromised. Defenders do not need to wait for perfect attribution before removing a preventable route to operational disruption.
Outlook
Renewed kinetic escalation is likely to increase intelligence tasking, opportunistic targeting, public claims, and pressure to produce visible effects. It does not fundamentally change the access paths available to Iranian operators. Identity compromise, trusted administration, remote-management tooling, service providers, exposed internet-facing systems, and high-trust individuals remain the mechanisms most likely to produce results.
We assess with high confidence that the near-term base case is continued espionage and access development accompanied by persona-led coercion and a large volume of lower-impact activity. That includes credential theft, mailbox and cloud compromise, recruitment-themed social engineering, exploitation of trusted service relationships, and inflated public claims. Most of it will be operationally persistent but individually less dramatic than the public discussion of “cyberwar” implies.
We assess with moderate confidence that Iran-linked operators will attempt selective disruption where three conditions coincide: usable access already exists, the victim has political or symbolic value, and the expected effect can be achieved without an unacceptable risk of escalation or exposure. Administrative and management systems are particularly relevant because they translate ordinary enterprise access into organization-wide effects.
OT activity will remain dangerous but uneven. The most likely incidents involve exposed systems, weak credentials, poorly controlled remote engineering, or known vulnerabilities rather than sophisticated manipulation of segmented safety-critical environments. A technically simple compromise can still cause serious consequences when the target environment is fragile or excessively connected.
Based on the public record, we assess with moderate confidence that a coordinated, national-scale campaign intended to disable the U.S. power grid or multiple critical sectors simultaneously is a lower-likelihood, high-impact contingency rather than the near-term base case. There is public evidence of repeated targeting, reconnaissance, and exploitation of exposed industrial systems, along with limited operational disruption.
There is no public evidence at the time of writing of the synchronized access, specialized preparation, and cross-sector execution required to support claims of an imminent nationwide grid-down operation.
Official U.S. statements confirm that USCYBERCOM and USSPACECOM layered non-kinetic effects into the opening military campaign to disrupt Iranian communications and sensor networks, but they do not disclose the specific systems, accesses, techniques, duration, or reversibility involved. That is representative of the wider conflict: analysts may know a cyber-enabled effect occurred while lacking the evidence to attribute a particular outage or reconstruct the operation.
Outside Iran, public claims are likely to outpace independently verified effects; inside Iran, consequential effects may outpace public reporting, and attribution will often remain harder than impact assessment.
Analysts should stop treating logos and claim volume as the principal units of analysis. The more useful unit is access plus mission plus dependency, evaluated against evidence quality. Security teams should focus on the trusted pathways that let an otherwise ordinary compromise become wartime leverage.
Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
The Handala hacking group claims it has targeted California Water Service, leaking 5GB of customer database and GPS network files in its latest infrastructure attack.
Notes the May 2026 Dark Web Breach Incident Trend Report is organized around the major cases of Data Breaches posted on the deep web and dark web forums. due to the nature of the source, some of the information may not be fully verifiable as to whether it is true or not, and is therefore […]
US Marines stationed around the Persian Gulf have been receiving WhatsApp messages from strangers suggesting they call home and make their final goodbyes.
Read more in my article on the Hot for Security blog.
Researchers have reverse-engineered a piece of malware named Fast16. It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet:
“…the Fast16 malware was designed to carry out the most subtle form of sabotage ever seen in an in-the-wild malware tool: By automatically spreading across networks and then silently manipulating computation processes in certain software applications that perform high-precision mathematical calculations and simulate physical phenomena, Fast16 can alter the results of those programs to cause failures that range from faulty research results to catastrophic damage to real-world equipment.”
Bellingcat has identified at least 80 police stations or infrastructure related to law enforcement agencies and the Basij paramilitary group that has been damaged or destroyed in the first three weeks of the United States and Israel’s war against Iran. Experts told Bellingcat that bothcountries aim to degrade the Iranian regime’s “repressive capacity”.
Combined, the US and Israel have conductedthousands of strikes during the course of the 2026 war in Iran. Targets range from Islamic Revolutionary Guard Corps (IRGC) sites, Navy vessels to Iranian weapons manufacturers.
In early March, a Bellingcat analysis using satellite imagery and available photos and videos identified police stations as another apparent target, with at least 15 damaged or destroyed in the capital, Tehran.
We also identified multiple strikes against police infrastructure in the country’s north and west; these areas were targeted by the Israel Defence Forces according to a map released by the IDF on March 31.
“We are providing the brave people of Iran with the conditions to take their destiny into their own hands,” declared the Israeli Ministry of Foreign Affairs official X account, along with a photo of a destroyed police station.
اینجا کلانتری ۱۲۱ سلیمانیه در خیابان نبرد تهران بود.
ما شرایطی را برای مردم شجاع ایران فراهم میکنیم تا سرنوشت خود را در دست بگیرند. pic.twitter.com/VSm6YVvIwZ
In all, the majority of strikes Bellingcat analysed focused on police stations (30 incidents) and command centers or headquarters (29 incidents). Locations also include sites related to Basij, a plainclothes paramilitary organisation (9) affiliated with the IRGC that were “involved in the deadly crackdown” of protests in January 2026, others are associated with special forces (3) and traffic (2) or diplomatic (2) police compounds.
Due to commercial satellite companies limiting access to imagery over Iran and neighbouring countries we relied on Sentinel-2 imagery data to help verify the incidents, as well as videos and photos, some of which were also verified by independent geolocators and contributors to the Geoconfirmed volunteer community and confirmed by Bellingcat researchers.
Location data was partly determined using open source mapping data either from Wikimapia, OpenStreetMap or Google Maps. When video footage or photos were available for incidents reportedly targeting police stations, the location was verified with geolocation and satellite imagery analysis using either Planet Labs medium resolution PlanetScope data (restricted to imagery collected by March 9) or low resolution Sentinel-2 data.
Some locations were discovered utilising location data taken from OpenStreetMap using Overpass Turbo and comparing that with available Sentinel-2 data throughout Iran.
Map showing geolocated incidents in Iran. Click the markers to view the coordinates, sources, and verification notes. Map: Bellingcat/Miguel Ramalho
A Problem of Scale
Israel has released multiplevideos showing the targeting of bases and checkpoints belonging to the Basij. In mid-March, the IDF announced the killing of the paramilitary group’s commander, Gholamreza Soleimani.
Targeting the Basij is part of Israel’s and the US’ agenda “to degrade the regime’s repressive capacity,” Ali Vaez, the director of International Crisis Group Iran Project, told Bellingcat. Police stations are “not involved in repression in the way that crowd control police or Basij centers are”, so targeting them “appears more aimed at preventing the Islamic Republic from being able to maintain control internally,” he said.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Vaez told Bellingcat that, when considered alongside the broader range of targets, including industrial factories, the widespread targeting of police stations is part of a strategy “to make Iran ungovernable for the existing regime or whatever comes after”.
Vaez was skeptical about the short term effects: “It’s a problem of scale. Iran is such a large country, even if you are able to completely destroy, not just degrade, the capacity of the regime in policing, oppressing, etc – it really requires not just maybe weeks but maybe months if not years.”
The Risk of Civilian Casualties
As of April 7, the Iranian Human Rights Activists News Agency estimates there’ve been more than 1,700 civilian fatalities during the war.
Several police stations are situated in densely populated urban areas such as Tehran. Stations are used by civilians for various reasons including renewing driving licences, so if these buildings are targeted “during working hours and not in the middle of the night then risk is higher for these people,” Vaez said.
Map showing geolocated incidents in Tehran. Click the markers to view the coordinates, sources, and verification notes.Map: Bellingcat/Miguel Ramalho
A recent joint Airwars, Center for Civilians in Conflict and Human Rights Activists in Iran report detailing the first month of civilian casualties included a section on the worsening situation for detainees in Iranian prisons — including police stations that have been targeted.
“I was detained in the holding cell of [Police Station 148] for ten days, along with four other activists. Now it looks like nothing is left of that station but ruins. I can’t even recognize where the detention area was. I keep wondering what happened to the people who were being held there during the attack. – Activist, told HRA upon seeing photos of the police station after recent US/Israeli airstrikes.”
Footage shared and geolocated by the BBC’s Shayan Sardarizadeh showed Police Station 148 damaged after an apparent strike in mid-March.
The main building of Tehran’s 148 police station and its courtyard, located on Enghelab Street, has been severely damaged in air strikes conducted on Friday.
The adjacent Hamoon Theatre also sustained some damage.
One destroyed police station identified by Bellingcat in the city of Mahabad in northwestern Iran led to apparent damage to an Iranian Red Crescent Society building located next door. According to Iran’s Tasnim News agency (an IRGC-affiliated media outlet sanctioned by the EU, the US and Canada), one Red Crescent employee was injured in the attack.
The police station adjacent to the Red Crescent building isn’t identified on any mapping services, though there are reports “Police Station 11” was targeted the same day.
Annotated Google Earth image showing the location of a destroyed police station and partially destroyed Red Crescent building in Mahabad, West Azerbaijan Province, Iran. A video shared on Telegram by mamlekate on March 6 shows the view of the destruction from the ground. Buildings behind the destroyed police station match with those seen in the Google Earth imagery.
Israel has also targeted checkpoints operated by Basij members.
Bellingcat examined two cases showing Israeli strikes on checkpoints while civilians were passing. In one video, a strike hits a checkpoint as five motorbikes and a vehicle go by.
View of a Basij checkpoint in Tehran targeted by the IDF. Immediately before the explosion is visible in the video, there are five motorbikes and a car next to the checkpoint. Source: YouTube/IDF
In another IDF video, a yellow bus is immediately adjacent to the checkpoint when it is hit. It is unclear how many people were on the bus at the time of the strike or if anyone was injured.
View of a Basij checkpoint in Tehran targeted by the IDF. Immediately before the explosion, there is a yellow bus visible next to the targeted checkpoint. Source: IDF
“I have been watching the reporting on these Basij strikes and the use of the Mikholit in particular in open urban areas. It is IDF standard—using precision munitions and even sometimes “low collateral” munitions but in a reckless manner that still puts the civilian population at risk,” Wes J. Bryant, a defence and national security analyst formerly with the Pentagon’s Civilian Protection Center of Excellence told Bellingcat.
Questions Over Legality
International Humanitarian Lawdefines civilians as “persons who are not members of the armed forces”. Police officers fall under that definition, according to Adil Haque, Professor of Law at Rutgers University and Executive Editor at Just Security. “As a rule, police are civilians and may not be attacked unless they take a direct part in hostilities,” Haque told Bellingcat. National security analyst Bryant agreed, adding that targeting police “does not stand up to legal scrutiny”.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
In an email to Bellingcat, the IDF noted “that the police form part of Iran’s internal security apparatus, which also forms part of Iran’s armed forces, under Iran’s own domestic legislation. In every strike, the IDF takes feasible precautions in order to mitigate incidental harm to civilians and civilian objects to the extent possible under the circumstances.”
Police are indeed “part of the country’s armed forces. By that logic, anything with a flag on it is a legitimate target,” Ali Vaez, the director of International Crisis Group Iran Project, said.
Although Basij is a paramilitary group, any strikes against it would require precautions to minimise harm to civilians, Haque told Bellingcat. “Since the hostilities almost entirely involve aerial bombardment, the concrete and direct military advantage anticipated from strikes on Basij members who qualify as combatants is extremely low, so significant harm to nearby civilians would be disproportionate and illegal,” he said.
When asked about potential civilian casualties in the checkpoint strikes, the IDF told Bellingcat that since the Basij are subordinate to the IRGC and are therefore part of the armed forces, they are regarded as lawful military targets. Regarding the checkpoint strikes specifically, they stated “precision munitions and surveillance means were used in the strikes, as part of the precautions taken under the circumstances to mitigate expected incidental harm”.
Bellingcat reached out to US Central Command (CENTCOM) to ask if the US had any role in the police station strikes identified but received no official comment at the time of publication.
Miguel Ramalho and Felix Matteo Lommerse contributed to this report.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Bluesky is back online after a roughly 24-hour DDoS attack disrupted services, with the Iran-linked 313 Team claiming responsibility and no data breach reported.
Alerts this report is a compilation of trends centered on hacktivists operating on the deep web and dark web. some alleged attacks are labeled as observations due to limited independent technical verification. Major Issues Handala’s multi-pronged offensive stood out. The group used a combination of psychological warfare and subversive attacks, including a claimed FBI-linked domain […]