Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-disruptionstate-sponsored-espionagegovernment-diplomatic-threatcritical-infrastructure-threat

US–Israel Cyber Operations Against Iran and Expected Iranian Retaliation

Updated 3mo agoFirst seen Mar 2, 20262 sources

Reporting described a major escalation in cyber warfare tied to US and Israeli military operations against Iran, with claims of widespread disruption inside Iran alongside information operations. One account said Iran experienced a near-total digital blackout (connectivity dropping to ~4% of normal), outages affecting government services and communications, and media/PSYOPS-style intrusions (e.g., defacements/injections on pro-regime sites, hijacked messaging via a widely installed prayer app, and interference with broadcast feeds). The same narrative framed the activity as part of a coordinated campaign (described as Operation Roaring Lion / Epic Fury) and positioned it as a continuation of long-running US–Israel vs. Iran cyber escalation.

Threat intelligence and security firms warned that Iran-linked actors were already mobilizing for reprisal activity against Israel and potentially Western/allied targets. Cited reporting said Anomali assessed multiple Iranian groups (including MuddyWater, APT42, and APT33) as “activated and retooling,” while noting an unusual lack of visibility into APT34 that it interpreted as possible covert pre-positioning rather than inactivity. Flashpoint was cited as observing Iran-linked Handala Group activity targeting Israeli industrial control systems (ICS) and claiming disruption to manufacturing/energy distribution, alongside claims of data theft affecting an Israeli healthcare organization; the overall guidance was to expect heightened Iranian cyber operations in the wake of kinetic strikes.

Share:
US–Israel Cyber Operations Against Iran and Expected Iranian Retaliation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 1, 20264mo ago

Iran-linked actors reported targeting Israeli ICS and Western networks

Threat reporting said Iran-linked actors, including the Handala Group and allied coalitions, were targeting Israeli industrial control systems and claiming disruptions. The same reporting described DDoS activity, data-wiping, and attempted wiper deployments against U.S., Israeli, and broader Western targets as early signs of escalation.

Threat intelligence firms warn of broader Iranian cyber retaliation

By 2026-03-01, multiple security firms assessed that Iranian state-aligned and proxy cyber activity was likely to intensify against U.S., Israeli, and other Western organizations. The warnings cited activation and retooling of groups including MuddyWater, APT42, and APT33, as well as the possibility of covert pre-positioning by APT34.

Hacktivist targeting of Israel and Gulf states surges after strikes

In the 24 hours following the strikes, pro-Iranian and pro-Palestinian hacktivist activity increased sharply, with Israel becoming the top reported target and Gulf states entering the top five. Reported activity included mostly low- to medium-sophistication DDoS attacks and website defacements, alongside claims of more serious breaches and initial-access sales involving CCTV, RDWeb, and SCADA/PLC environments.

Feb 28, 20264mo ago

Iran experiences near-total internet blackout during strikes

Around the start of the 2026-02-28 strikes, Iran suffered a major internet connectivity drop or near-total blackout. One source says the outage was likely a self-imposed shutdown by Iranian authorities, while another notes claims it may have related to attacks on communications infrastructure, with attribution unclear.

PSYOPS compromises hit Iranian media and communications platforms

Coinciding with the launch of Operation Roaring Lion, pro-regime Iranian news sites were reportedly compromised to inject psychological-operations content, and the BadeSabaa prayer app was allegedly hijacked to display surrender messages. Iranian national TV Channel 3 satellite streams on IntelSat were also reportedly hijacked to broadcast speeches by Donald Trump and Benjamin Netanyahu.

Operation Roaring Lion begins against Iranian targets

On 2026-02-28, the U.S. and Israel launched Operation Roaring Lion, a joint military campaign targeting Iranian military, nuclear, and government assets. The operation marked the trigger for the cyber and information activity described in the references.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

43 LINKEDOpen in app
Malware
4 linked
Organizations
17 linked
eBayBank SepahNobitexIntelsatSaudi AramcoUnion Bank of IsraelZENDATAEITAABadeSabaaArchive of Our OwnCheck Point Software TechnologiesFlashpointNetBlocksMicrosoft CorporationSentinelOneAnomaliClalit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.