Iranian officials and affiliated voices signaled a sharper turn toward cyber retaliation during the U.S.-Israeli conflict, with the Islamic Revolutionary Guard Corps threatening major U.S. technology companies including Apple, Google, and Meta if more Iranian leaders were killed. North Carolina and other U.S. defenders were urged to stay on heightened alert as state officials cited increased nation-state activity and MS-ISAC warned that Iran is more likely to conduct disruptive or destructive operations such as wiper attacks, website defacements, and DDoS activity than conventional ransomware. Reporting tied the threat environment to a claimed Handala wiper attack on medical device maker Stryker and to broader concern that election-related websites and other civilian targets could face low-level disruption.
Multiple assessments said Iran’s immediate cyber response appeared limited because military strikes, leadership losses, and internet disruptions had temporarily degraded its operations, but argued that the conflict is likely to push Tehran to invest more heavily in cyber capabilities over time. Analysts described cyber operations as a cheap, resilient, and globally deployable tool that can survive bombing and compensate if Iran’s other means of projecting power are weakened. The debate unfolded alongside criticism that Washington’s cyber strategy is too offense-heavy and institutionally underpowered, with gaps in leadership, pressure on U.S. Cyber Command, and reduced civilian cyber capacity leaving U.S. networks and critical infrastructure more exposed as Iranian retaliation risks grow.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
A Risky Bulletin podcast episode published on April 7 discussed how Iran’s cyber forces had been used during the ongoing war. Its show notes referenced reporting about a plan to kill Ali Khamenei and claims that 50 companies were wiped.
Iran's Revolutionary Guards publicly threatened retaliatory action against major U.S. technology companies including Apple, Google, and Meta if additional Iranian leaders were killed. The statement warned that relevant units could be destroyed beginning at 8:00 pm Tehran time on Wednesday, April 1.
Risky Biz reported that the European Union sanctioned Iranian contractor Emennet Pasargad and others for cyberattacks.
A Risky Bulletin podcast episode published on March 19 argued that a successful U.S. war outcome against Iran could leave the country relying more heavily on cyber capabilities because they are resilient, cheap, and fast to employ.
Risky Biz reported a claimed Handala wiper attack targeting medical device maker Stryker as part of the cyber activity discussed around the conflict with Iran.
Risky Biz reported that Iran’s immediate cyber retaliation against U.S. and Israeli strikes had been limited, likely because military action, leadership losses, and internet disruptions had temporarily degraded Iranian cyber operations.
A March 17 Risky Bulletin podcast episode examined how bombing Iran could change Iranian hacker incentives and push the state to rely more heavily on cyber operations if other means of projecting power were degraded.
North Carolina’s technology department issued a public warning about heightened cyber risk, citing recent intelligence indicating increased activity by nation-state actors. State officials said the security operations center was on high alert and urged governments, businesses, and residents to strengthen defenses.
A Council on Foreign Relations article says the Trump administration had newly released a cyber strategy and criticizes it as too brief, overly offense-focused, and misaligned with major threats such as China and Iran.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
koreatimes.co.kr
Open sourcerisky.biz
Open sourcenews.risky.biz
Open sourcerisky.biz
Open sourcestatescoop.com
Open sourcecfr.org
Open sourcerisky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.