Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-disruptioncritical-infrastructure-threathacktivist-operationgovernment-diplomatic-threat

Cyber and information operations intensify amid US-Israel strikes on Iran under “Operation Epic Fury”

Updated 3mo agoFirst seen Mar 3, 20263 sources

US and Israeli military action against Iran under “Operation Epic Fury” has been accompanied by heightened cyber activity and public acknowledgment of offensive cyber operations. Reporting indicated a surge of pro-Iranian activity including DDoS attacks, attempted compromises, and targeting of critical infrastructure, with researchers warning that Iranian state-linked actors tied to the IRGC and MOIS, as well as aligned hacktivists, are likely to sustain retaliatory operations aimed at economic, reputational, and potentially physical disruption. Separately, reporting alleged Israeli intelligence conducted long-running surveillance by compromising Tehran traffic cameras, exfiltrating encrypted video and telemetry to servers outside Iran to build “pattern of life” intelligence on senior leadership movements.

The Pentagon also elevated the visibility of cyber as a warfighting domain, with the Chairman of the Joint Chiefs describing coordinated space and cyber effects used to “disrupt, degrade, and blind” Iranian communications and sensor networks, though without operational detail. In parallel but unrelated to the Iran conflict, Russia’s internet regulator Roskomnadzor and the Russian Defense Ministry reported a “complex multi-vector” DDoS incident that temporarily disrupted multiple government sites, with traffic attributed to botnets and servers across several countries and continued user-reported instability after initial containment.

Share:
Cyber and information operations intensify amid US-Israel strikes on Iran under “Operation Epic Fury”
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 3, 20264mo ago

Researchers report surge of pro-Iranian cyberattacks on Israel and regional targets

Security researchers reported a barrage of cyberattacks by IRGC- and MOIS-linked actors and aligned hacktivist groups, including DDoS attacks, network compromises, data exfiltration, and destructive activity such as wipers and pseudo-ransomware. Reported targets included Israeli and US-aligned entities in energy, municipal, telecom, defense, media, and religious-city infrastructure, with claims also involving Saudi and UAE assets.

US cyber forces conduct offensive operations in Operation Epic Fury

During the Iran campaign, USCYBERCOM and SPACECOM delivered non-kinetic effects that disrupted and degraded Iranian communications and sensor networks as part of Operation Epic Fury. Pentagon officials said these cyber operations were integrated with land, air, and sea operations to reduce Iran's ability to coordinate and respond.

US-Israeli strike on Iran triggers broader conflict and cyber retaliation

A joint US-Israeli military strike on Iran set off a wider conflict that researchers say catalyzed a cyber retaliation ecosystem involving Iranian state-linked actors and aligned hacktivist groups. The resulting activity was described as regionally concentrated but capable of broader spillover.

Israeli intelligence reportedly compromises Tehran traffic cameras over years

Israeli intelligence services allegedly hacked traffic cameras across Tehran over multiple years to monitor the movements and security patterns of Ayatollah Ali Khamenei and other senior Iranian officials. The operation reportedly collected encrypted surveillance data and transmitted it to servers in Tel Aviv and southern Israel.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Malware
1 linked
Organizations
10 linked
Check Point Software TechnologiesCisco SystemsThe RegisterAmazon Web ServicesElbit SystemsFlashpointPalo Alto NetworksSaudi AramcoGoogleAbu Dhabi Gas Industries
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cyber and information operations intensify amid US-Israel strikes on Iran under “Operation Epic Fury” | Mallory