Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationthreat-infrastructure-trackinggovernment-diplomatic-threatstate-sponsored-espionage

Iran-linked cyber activity escalates alongside Middle East hostilities, including IP camera targeting and DDoS campaigns

Updated 3mo agoFirst seen Mar 4, 20263 sources

Iran-attributed cyber activity increased alongside escalating Middle East hostilities, with researchers reporting intensified targeting of internet-connected IP cameras across Israel, Qatar, Bahrain, Kuwait, the UAE, Cyprus, and later specific areas in Lebanon. Check Point assessed the activity as consistent with Iranian doctrine of leveraging compromised cameras for operational support and battle damage assessment (BDA) tied to missile operations, noting that tracking camera-targeting infrastructure may provide early warning of potential follow-on kinetic activity.

Separately, Radware reported 149 Iran-linked DDoS attacks observed between Feb 28 and Mar 2, largely aimed at government entities in the Middle East, and attributed most activity to three hacktivist groups: Keymous+, DieNet, and Conquerors Electronic Army. Additional OSINT-driven infrastructure analysis described broader Iranian state-aligned clustering using indicators such as ASN patterns and TLS fingerprints to map suspected operational infrastructure, while commentary from industry sources emphasized that destructive “wiper” malware remains a key concern (citing families including ZeroCleare, Meteor, Dustman, DEADWOOD, and Apostle). A separate ransomware “monthly state” roundup and a detection-engineering newsletter were not specific to this Iran/Middle East activity and do not materially support the incident reporting.

Share:
Iran-linked cyber activity escalates alongside Middle East hostilities, including IP camera targeting and DDoS campaigns
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 4, 20264mo ago

Check Point publishes report linking camera targeting to warfare support

On March 4, Check Point Research published its assessment that the observed targeting of Hikvision and Dahua cameras aligns with Iranian doctrine of using compromised cameras for operational support and battle damage assessment related to missile operations. The report also recommended reducing camera exposure, patching, network segmentation, strong credentials, and monitoring for suspicious access.

Hunt.io publishes analysis of 19 Iran-linked threat clusters and IOCs

Hunt.io released research mapping 19 Iran-linked threat groups using infrastructure pivots such as ASNs, TLS certificates, hashes, and open directories. The report also published a subset of derived indicators of compromise and monitoring guidance for U.S. and Israeli organizations.

Mar 1, 20264mo ago

Camera-targeting activity shifts focus to areas in Lebanon

On March 1, the observed IP camera targeting expanded or shifted to specific areas in Lebanon amid the ongoing Middle East conflict. Check Point linked the activity to the same broader Iran-nexus campaign targeting exposed surveillance devices.

Feb 28, 20264mo ago

Intensified regional targeting of Hikvision and Dahua cameras begins

Beginning on February 28, Check Point Research observed intensified scanning and exploitation attempts against Hikvision and Dahua IP cameras across Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus. The infrastructure used was attributed to Iran-nexus threat actor activity and included commercial VPN exit nodes and VPS providers.

Jan 14, 20265mo ago

Iran-linked infrastructure targets IP cameras in Israel and Qatar

Check Point Research observed earlier related activity on January 14–15 targeting Hikvision and Dahua IP cameras in Israel and Qatar. The activity was later assessed as consistent with Iran-nexus efforts to access exposed cameras for operational support and possible battle damage assessment.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

58 LINKEDOpen in app
Affected products
6 linked
Mullvad VpnNordvpnNordvpnTelegramWhatsappCloudflare
Organizations
22 linked
Check Point Software TechnologiesHikvisionSurfsharkProtonNord SecurityMullvad VPNZhejiang Dahua TechnologyRadwareAT&THunt.ioCloudflareMeta PlatformsSaudi AramcoNameCheapMicrosoft CorporationTelegramLet's EncryptAnomaliEDIS GmbHAkton d.o.o.Hosterdaddy Private LimitedM247 Europe SRL
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.