Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageembedded-device-vulnerabilitythreat-infrastructure-trackingremote-access-implant

Iran-Linked Cyber Activity Escalates Amid Middle East Conflict

Updated 3mo agoFirst seen Mar 5, 20269 sources

Iran-nexus cyber activity intensified alongside regional military escalation, with multiple reporting streams describing both opportunistic and targeted operations. Check Point Research observed a coordinated campaign to compromise internet-connected IP cameras across Israel, the UAE, Qatar, Bahrain, Kuwait, Lebanon, and Cyprus, with spikes in exploitation attempts aligning to geopolitical events; activity was traced to infrastructure linked to Iran-nexus actors using commercial VPN exit nodes (e.g., Mullvad, ProtonVPN, Surfshark, NordVPN) and VPS infrastructure to mask origin, and the most targeted vendors were Hikvision and Dahua. Separately, Symantec reported Seedworm (MuddyWater/Temp Zagros/Static Kitten) activity on multiple U.S. and Canadian organizations beginning in February 2026, including a U.S. bank, airport, non-profit, and the Israeli operations of a U.S. software supplier to defense/aerospace; Symantec identified a previously unknown backdoor dubbed Dindoor (leveraging the Deno runtime) and a Python backdoor Fakeset, with malware signed using certificates issued to “Amy Cherne” (and in some cases “Donald Gay”), and noted attempted data exfiltration using Rclone to a Wasabi cloud storage bucket.

Additional coverage indicates broader pro-Iranian cyber activity but is less specific to the above intrusions. ASEC’s weekly “Ransom & Dark Web Issues” roundup flags pro-Iranian/pro-Islamist hacktivist attacks against Middle Eastern and pro-Western targets, but provides limited technical detail in the excerpt. A podcast episode describing “Iran’s 12 days of cyber war” and global OT targeting (including Unitronics PLCs) is largely commentary and retrospective framing rather than a discrete, verifiable incident report, and two other items in the set (a Russia-linked APT28 phishing/malware campaign in Ukraine and a China-nexus UAT-9244 telecom intrusion set in South America) describe unrelated threat activity outside the Iran-focused escalation.

Share:
Iran-Linked Cyber Activity Escalates Amid Middle East Conflict
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Mar 6, 20264mo ago

Ctrl-Alt-Intel claims access to a Seedworm VPS and recovered data

Help Net Security reported that the Ctrl-Alt-Intel collective claimed to have accessed a Seedworm/MuddyWater VPS in the Netherlands and recovered command-and-control tooling and victim data. The claim also described broader targeting across Israel, the Middle East, and the U.S., along with tradecraft such as password spraying, CVE exploitation, Ethereum-based C2 resolution, and multiple exfiltration channels.

Mar 5, 20264mo ago

Researchers publish details of Iran-linked IP camera exploitation

Reporting on Check Point's findings revealed that Iranian-aligned actors were exploiting five known vulnerabilities and exposed access paths in Hikvision and Dahua devices across the Middle East. The disclosure highlighted the risk that compromised cameras could provide real-time visual intelligence for military targeting and battle damage assessment.

Symantec discloses Seedworm campaign and new Dindoor backdoor

Symantec reported that Seedworm/MuddyWater had targeted multiple U.S. and Canadian organizations since February 2026 and identified a new Deno-based backdoor named Dindoor, along with a Python backdoor called Fakeset. The report also described attempted exfiltration using Rclone to a Wasabi bucket and attribution evidence from reused code-signing certificates.

Mar 4, 20264mo ago

Hacktivist groups attack Middle Eastern and pro-Western targets

ASEC said pro-Iranian and pro-Islamist hacktivist groups carried out cyber attacks against Middle Eastern and pro-Western targets. The roundup framed this as part of the threat activity observed in early March 2026.

Morpheus ransomware attacks a South Korean plating company

ASEC reported that the Morpheus ransomware operation attacked a plating company in South Korea. The incident was included in ASEC's week 1 March 2026 ransomware and dark web roundup.

Ailock ransomware resumes activity and republishes victim data

ASEC reported that the Ailock ransomware group became active again and republished data from previous victims. The roundup did not provide a more specific date than its week-one-of-March reporting window.

Feb 28, 20264mo ago

MuddyWater activity increases after regional escalation

Researchers said Seedworm/MuddyWater operations increased after the February 28 strikes, with existing footholds in victim networks potentially positioned for espionage, disruption, or future destructive actions.

U.S.-Israeli strikes on Iran precede increase in Iranian cyber activity

Multiple reports said Iranian cyber operations intensified after U.S. and Israeli military strikes on Iran. The cited date for the strikes was February 28, 2026, and researchers assessed some intrusions had been pre-positioned before the conflict escalation.

Feb 25, 20264mo ago

Iranian actors launch IP camera targeting campaign in the Middle East

Check Point researchers observed an Iran-nexus campaign targeting internet-exposed Hikvision and Dahua cameras across multiple Middle East countries starting in late February 2026. The activity was assessed as supporting intelligence collection for possible kinetic operations.

Feb 1, 20265mo ago

Iran-linked actors begin intrusions into U.S. and Canadian organizations

Researchers reported that Seedworm/MuddyWater activity inside multiple organizations began in early February 2026, affecting a U.S. bank, a U.S. airport, nonprofits in the U.S. and Canada, and the Israeli operations of a U.S. software supplier tied to defense and aerospace.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

72 LINKEDOpen in app
Affected products
13 linked
NordvpnDenoNordvpnRcloneFacebookTelegramMullvad VpnAnydeskScreenconnectLinkedinPythonGmailMicrosoft Office
Organizations
32 linked
BroadcomWasabi TechnologiesKasperskyMicrosoft CorporationGoogleStarlinkCheck Point Software TechnologiesBackblazeThe RegisterBeyondtrustHikvisionSurfsharkNobitexBrookings InstitutionSaudi AramcoConnectwiseAnyDesk Software GmbHProtonNordvpnSpaceXNord SecuritySecurity AffairsMullvad VPNASEC BlogEgyptAirZhejiang Dahua TechnologyAilockMorpheusSharjah National Oil CorporationIsrael Opportunity EnergyDeno LandSuzu Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Iran-Linked Cyber Activity Escalates Amid Middle East Conflict | Mallory