Reporting and analysis indicate Iranian threat actors have increasingly integrated cyber operations with kinetic objectives following the Feb. 28 U.S.-Israel strikes on Iran. Check Point Research assessed intensified targeting of IP cameras—notably devices from Hikvision and Dahua—across Israel and parts of the Gulf (including Qatar, Bahrain, Kuwait, the UAE, and Cyprus), with activity patterns suggesting use for operational support and battle damage assessment tied to missile launches; the research highlights that monitoring camera-targeting infrastructure may provide early warning of follow-on kinetic activity. Separately, commentary on Iranian cyber posture argues the apparent “quiet” is not simply loss of capability, describing a resilient, decentralized operating model and noting prior disruption to leadership and infrastructure (e.g., “Operation Epic Fury”) without eliminating Iran’s ability to conduct operations.
Additional reporting described U.S. Cyber Command participation in coordinated cyber/space actions intended to disrupt Iranian communications and sensor networks during the opening phase of hostilities, and cited claims (attributed to external reporting) that compromised traffic cameras and penetrated mobile networks were used to support real-time intelligence for targeting decisions in Tehran. Other items in the set cover unrelated law-enforcement actions against cybercrime services (e.g., takedowns of Tycoon2FA and LeakBase, and a Phobos ransomware guilty plea), a separate report on suspected DPRK-linked intrusions against cryptocurrency firms, and a general discussion of ransomware market dynamics post-LockBit; these do not materially add to the Iran cyber-kinetic camera/communications targeting narrative.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
During the current conflict, Iranian cyber operations reportedly included thousands of wiper attacks against Israeli targets, with Check Point saying roughly 50 Israeli companies were successfully compromised. Researchers described the activity as showing a new level of scale, effect, and sophistication alongside coordinated mass text messaging and camera-enabled targeting.
CrowdStrike assessed that IRGC-linked retaliatory cyberattacks following the strikes were relatively muted and limited in scope. At the same time, it observed increased pro-Iranian Russian hacktivist targeting of US entities’ ICS/SCADA and CCTV networks.
By early March 2026, Flashpoint highlighted additional Iran-linked activity including ICS targeting, alleged phishing-led logistics sabotage against Jordan’s silos and supply company, and DDoS attacks on government entities in the UAE and Bahrain. The reporting also referenced propaganda operations and missile strikes against data centers as part of a broader hybrid campaign.
Iran responded by implementing a nationwide internet blackout, sharply limiting the duration and impact of the opposing cyber campaign. Analysis described the decisive cyber window as lasting only a few hours before connectivity was cut.
During the campaign, push notifications were reportedly sent through the Iranian prayer app BadeSaba as part of cyber-enabled psychological operations. The compromise was also assessed as potentially valuable for intelligence collection because of the app’s location access.
In the same early operational window, localized disruption of mobile communications near Ali Khamenei’s compound reportedly hindered protective warnings during an assassination operation. The disruption was described as part of cyber support to kinetic action.
During the opening hours of the campaign against Iran, US and Israeli cyber operations reportedly disrupted communications and sensor networks to support time-sensitive kinetic targeting. Reporting cited compromised Tehran traffic cameras and penetrated mobile networks as sources of real-time intelligence.
Beginning February 28, 2026, Check Point Research observed intensified targeting of Hikvision and Dahua IP cameras in multiple Middle Eastern countries and Cyprus. The activity was assessed as supporting operational reconnaissance and battle-damage assessment for missile operations.
On February 28, 2026, US and Israeli strikes on Iran marked the start of a new phase in which cyber activity was described as being integrated with kinetic military action. Subsequent reporting framed this as an emerging Iranian cyber-kinetic doctrine.
During the June 2025 Israel-Iran conflict, Iranian operators were reported to target IP cameras in patterns later cited as an early example of cyber activity supporting military operations. One reported case said Iran controlled a street camera before a strike on Israel’s Weizmann Institute of Science.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourceshieldworkz.com
Open sourcedarkreading.com
Open sourcelawfaremedia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.