Amazon security leaders have revealed that nation-state actors are increasingly using cyber operations to gather intelligence that directly supports physical military actions. According to Amazon Threat Intelligence, groups such as Iran-backed Imperial Kitten and MuddyWater have conducted digital reconnaissance to identify and scope targets, with the collected data feeding into real-world kinetic strikes. Amazon's unique threat visibility, leveraging its MadPot honeypot systems, opt-in customer data, and industry partnerships, has enabled the detection of these coordinated campaigns, which blur the traditional boundaries between cyber and physical security.
This emerging threat model, described as 'cyber-enabled kinetic targeting,' requires organizations to rethink their approach to risk management, as industries not previously considered high-value targets—such as shipping, transportation, and electronics—are now at risk due to the intelligence value of their systems. Amazon's security executives emphasize that digital and physical security can no longer be siloed, urging both private and public sectors to adapt to this new operational reality where cyber intrusions are a precursor to military objectives and physical attacks.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
CloudSEK reported that Iran-linked APT35 (Charming Kitten) conducted multi-year cyber reconnaissance across GCC countries, including profiling and in some cases breaching critical infrastructure in the UAE, Saudi Arabia, Qatar, and other states. The report said the activity preceded coordinated missile strikes, suggesting the cyber operations may have supported kinetic targeting.
On November 19, 2025, Amazon published threat intelligence findings warning that nation-state actors are increasingly using cyber operations to gather targeting intelligence for real-world military strikes. The report highlighted examples involving Iran, Russia, and China and urged defenders to integrate cyber and physical security models.
Amazon reported that Iran-linked group Imperial Kitten (Tortoiseshell) conducted digital reconnaissance against a vessel's AIS platform and CCTV systems days before a failed Houthi missile strike attempt in the Red Sea. The activity was presented as a concrete example of cyber-enabled kinetic targeting against maritime assets.
Amazon Threat Intelligence said Iran-linked group MuddyWater accessed live CCTV feeds in Jerusalem to support missile targeting, illustrating cyber reconnaissance used to inform physical strikes. The reporting ties the surveillance to missile attacks on Israel, though an exact date was not provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourceaws.amazon.com
Open sourcecsoonline.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.