Iranian state-sponsored threat actors have intensified their cyber operations, targeting government officials, defense sector personnel, and dissidents through sophisticated espionage and disruptive campaigns. The APT42 group, linked to Iran’s Islamic Revolutionary Guard Corps (IRGC), has launched the 'SpearSpecter' campaign, employing highly personalized social engineering tactics to compromise senior defense and government officials, as well as their family members. These operations involve building trust over extended periods and leveraging fake conference invitations or meetings to deliver malicious payloads. Other Iranian-linked groups, such as Ferocious Kitten, have focused on targeting dissidents and activists with spear-phishing attacks that deploy custom malware like MarkiRAT, which features advanced data exfiltration and persistence techniques.
In parallel, the DEV-1084 group, operating under the 'DarkBit' persona and closely associated with the Iranian state-linked MERCURY group, has conducted ransomware campaigns that prioritize destruction over financial gain. These attacks combine on-premises encryption with the mass deletion of cloud resources, effectively wiping out victim environments and aligning with broader strategic objectives of disruption and psychological impact. Technical analysis has revealed shared infrastructure and tools between DEV-1084 and MERCURY, further solidifying the connection to Iran’s Ministry of Intelligence and Security (MOIS). These coordinated campaigns underscore the evolving threat landscape posed by Iranian APTs, which blend espionage, destructive attacks, and advanced social engineering to achieve their objectives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Hacker News reported that Iranian hackers launched a spy operation dubbed SpearSpecter targeting defense and government entities. The reference indicates a distinct espionage campaign focused on high-value public-sector and defense-related targets.
SC Media reported on analysis of the Iran-linked Ferocious Kitten APT's operations, indicating new public documentation of the group's tactics and activity. The available reference does not provide a more specific event date beyond publication.
Reporting published in November 2025 describes DarkBit ransomware operations as being conducted by Iranian threat actors tracked as DEV-1084 and MERCURY. The references characterize DarkBit as part of Iran-linked offensive cyber activity rather than ordinary criminal ransomware.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcepicussecurity.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.