Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptionhacktivist-operationbotnet-infrastructuregovernment-diplomatic-threat

DDoS and Cyber Operations Escalate Amid Israel–U.S. Strikes on Iran

Updated 3mo agoFirst seen Mar 2, 202616 sources

Threat monitoring and situation reporting tied a surge in distributed denial-of-service (DDoS) activity and broader cyber disruption to the escalation of the Israel–U.S. conflict with Iran in late February 2026. NSFOCUS reported sustained DDoS targeting of Iranian IP space following internal unrest and rising U.S.–Iran nuclear tensions, describing both botnet-driven floods and reflection/amplification techniques against 259 Iranian IPs, including government, news, and network-infrastructure entities. As kinetic events intensified—particularly after Israel announced strikes on Iran—reporting described a sharp increase in DDoS activity and subsequent Iranian network control measures, including an internet shutdown intended to reduce exposure to anticipated cyberattacks.

CloudSEK characterized the period as a shift into hybrid conflict, citing coordinated Israeli–U.S. strikes (described as Operation Roaring Lion/Epic Fury) alongside what it called a major cyber campaign contributing to a near-total Iranian internet blackout and disruption to government services, media, and parts of energy and aviation. In parallel, Russia’s internet regulator Roskomnadzor and the Russian Defense Ministry reported a separate “complex multi-vector” DDoS incident that briefly disrupted access to multiple Russian government websites and related infrastructure (including the Main Radio Frequency Center), with traffic attributed to servers/botnets across several countries; no actor claimed responsibility. While DDoS is a common tactic in geopolitical crises, the Russian incident appears operationally and geographically distinct from the Iran-focused escalation reporting.

Share:
DDoS and Cyber Operations Escalate Amid Israel–U.S. Strikes on Iran
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

19 events from the most recent confirmed update back to the earliest known activity.

19 EVENTS
Mar 6, 20264mo ago

Symantec and Carbon Black cite suspicious MuddyWater-linked activity in North America

By March 6, Symantec and Carbon Black said the Iran-linked group MuddyWater remained active and pointed to suspicious activity affecting a US bank, a software company, an airport, and NGOs in the US and Canada. Another firm reported related infrastructure appeared to go quiet shortly before the war began.

Mar 4, 20264mo ago

Security firms warn Iran-linked groups are targeting internet-connected cameras

Check Point reporting highlighted intensified Iran-nexus targeting of internet-connected IP cameras across multiple Middle East locations. The activity was assessed as supporting missile targeting and battle-damage assessment rather than direct disruption.

US officials disclose cyber operations supported the assault on Iran

US officials publicly said cyber operations by US Cyber Command and US Space Command underpinned the opening phase of the strike campaign by disrupting Iranian defenses and communications. Reporting also said cyber-enabled intelligence collection helped identify targets.

Mar 3, 20264mo ago

Vendors report no confirmed large-scale Iranian state cyber campaign yet

By March 3, several firms including CrowdStrike and Recorded Future said they had not confirmed a major independently verified Iranian state-sponsored cyber offensive despite heightened risk and extensive public claims. Analysts warned that destructive or disruptive retaliation could still follow.

Malicious RedAlert Android app campaign targets Israelis

Researchers reported an SMS phishing campaign distributing a malicious Android APK masquerading as Israel's RedAlert missile warning app. The malware was designed to exfiltrate device and user data and included anti-analysis features.

Mar 2, 20264mo ago

Pro-Iran actors claim breach of Jordanian grain silo control systems

Flashpoint and other sources noted claims by pro-Iranian hacktivists that they had breached a Jordanian grain silo company's ICS/SCADA environment. The legitimacy of the claimed control-system intrusion remained unverified.

Researchers identify surge of coordinated hacktivist claims

By March 2, multiple intelligence firms reported a sharp increase in claimed activity by Iran-aligned and sympathetic hacktivist groups, including DDoS, defacements, and unverified hack-and-leak operations. Large-scale independently verified state-sponsored intrusions had not yet been confirmed.

Hacktivist campaign expands across countries and sectors

Between February 28 and March 2, hacktivist activity spread across the Middle East and beyond, with Radware counting 149 DDoS claims against 110 organizations in 16 countries. Government and public infrastructure organizations were the most heavily targeted.

Mar 1, 20264mo ago

Iran launches missile and drone retaliation under Operation Truthful Promise 4

Beginning March 1, Iran responded to the US-Israeli assault with missile and drone attacks against Israel, Gulf states, and US-linked bases. Sources describe this as the immediate kinetic retaliation phase of the conflict.

Feb 28, 20264mo ago

UAE and Gulf states report and foil cyberattack waves

Authorities in the UAE and other Gulf states reported waves of sophisticated cyberattacks in late February as the regional crisis escalated. The attacks were reportedly detected and blocked, allowing essential services to remain online.

DDoS activity against Iranian infrastructure surges after strike announcement

NSFOCUS recorded a major DDoS spike on February 28 after Israel announced strikes on Iran. The attacks hit Iranian government agencies, state media, universities, and national internet infrastructure.

Hacktivist retaliation wave begins after the strikes

Pro-Iran and aligned hacktivist groups began claiming DDoS attacks, defacements, and breaches immediately after the February 28 strikes. Orange Cyberdefense identified Hider Nex as an early actor launching one of the first DDoS attacks that day.

Cyber operations disrupt Iranian state services and media during strikes

Reports said the opening phase included large-scale cyber disruption affecting Iranian government services, state media outlets such as IRNA and ISNA, and military or communications systems. These non-kinetic effects were described as synchronized with the military assault.

Iran suffers near-total internet blackout during opening phase of conflict

Following the February 28 strikes, Iranian internet connectivity reportedly collapsed to roughly 1% to 4% of normal levels. Multiple sources assessed the outage as a regime-imposed shutdown or network-control measure amid fears of cyberattack and wartime disruption.

US and Israel launch coordinated strikes on Iran under Operation Epic Fury

On February 28, the United States and Israel began a joint strike campaign against Iran, described across sources as Operation Epic Fury and also as Operation Lion's Roar/Roaring Lion. Multiple reports say cyber and space operations supported the opening phase by disrupting Iranian defenses and communications.

Feb 27, 20264mo ago

Iranian threat actors stage malware and pre-position access before strikes

Security firms including Check Point and Binary Defense assessed that Iran-nexus actors conducted preparatory intrusions and staged malware ahead of the coming kinetic escalation. Activity included operations linked to Cotton Sandstorm and related tooling.

Feb 14, 20264mo ago

Iran-linked actors probe government APIs and mobile apps before conflict

Approov reported a surge of sophisticated probing against APIs and mobile applications used for government-related communications in the weeks before the war. The activity was assessed as infrastructure mapping and vulnerability reconnaissance.

Jan 9, 20265mo ago

DDoS attacks spike around Iranian protest milestone

NSFOCUS observed a notable spike in DDoS activity targeting Iranian assets around January 9, indicating the campaign was intensifying well before the later military confrontation. Targets included state-linked and national infrastructure systems.

Jan 4, 20266mo ago

DDoS activity against Iranian targets begins amid domestic unrest

NSFOCUS reported sustained event-driven DDoS activity against Iranian government, media, and internet infrastructure starting with domestic unrest in Iran. The campaign later expanded as geopolitical tensions increased.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

138 LINKEDOpen in app
Affected products
12 linked
AndroidTelegramAndroidSymantecMicrosoft OfficeGoogle DriveSpotifyItunesPowershellChatgptChatgptGoogle Drive
Organizations
53 linked
FlashpointCheck Point Software TechnologiesNetBlocksFoundation for Defense of DemocraciesFalconFeedsCloudflareInformation Security Media GroupBroadcomCarbon BlackFTI ConsultingCtrl-Alt-IntelPolySwarmMicrosoft CorporationTelecommunication Company of IranIranCellMobile Communication Company of IranAmazon Web ServicesGoogleCybleApproovFinancial TimesCrowdStrikeSophosTrend MicroCisco SystemsThe RegisterChainalysisXcape IncCequence SecurityLinkedinBinary DefensePalo Alto NetworksTenableInternational Business MachinesOktaIntellexaReliaQuestSaudi AramcoOpenaiNSFOCUSCloudSEKSC MediaAnomaliNextgov/FCWThe New York Times CompanyDefense OneTabnakMazeBoltCrowne PlazaKhaleej TimesDubai International AirportCybersecurity DiveSuzu Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.