U.S. agencies warned that Iran could target critical infrastructure operators as researchers and policy analysts described a cyber ecosystem that blends state-directed activity with nominally independent hacktivist groups. CSIS said Tehran uses this structure to support espionage, sabotage, influence operations, and plausible deniability, citing the CyberAv3ngers intrusions into U.S. water and wastewater systems as a prominent example after U.S. authorities tied the activity to officials in the Islamic Revolutionary Guard Corps Cyber-Electronic Command. The same reporting linked Iranian state organs, including the IRGC and MOIS, to affiliated groups such as APT33, APT35, APT34/OilRig, and MuddyWater.
The threat picture expanded as pro-Russia actors joined Iran-linked operations under #OpIsrael, with attacks reportedly including DDoS, claimed breaches, leaked CCTV footage, SQL injection, and data leaks against Israeli government, education, and municipal targets. Researchers said dozens of Russia-aligned and Iran-nexus actors appeared to be participating, while Radware separately reported retaliatory hacktivist DDoS activity tied to the regional conflict. U.S. officials and sector groups have monitored for spillover risk, warning that even if many operations are opportunistic or low sophistication, smaller U.S. infrastructure operators could still face disruptive, high-visibility attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Published reporting on 2026-06-29 cited Israel National Cyber Directorate director-general Yossi Karadi as saying Israel recorded about 4,800 hostile cyber incidents in June 2026, up from roughly 1,600 in June 2025 during Israeli operations against Iran. He said the activity targeted critical infrastructure, central organizations, SMBs, and the public, and that while critical infrastructure attacks were prevented, some easier-to-breach organizations had systems wiped.
On 2026-05-27, Israel National Cyber Directorate director-general Yossi Karadi said Iranian state-aligned hackers had become more organized and collaborative during and after the recent war, and were using AI to improve large-scale deceptive text-message campaigns. He said Iranian cyber operations continued against Israeli, American, and regional targets even as the level of physical conflict changed.
A federal advisory reported that Iran-linked hackers recently disrupted multiple U.S. oil and gas and water facilities by targeting internet-facing programmable logic controllers, forcing some operators to switch to manual operations and causing financial losses. Investigators also said the attackers in some cases attempted to deploy destructive malware, including wipers, raising concerns about potential physical and safety risks.
On 2026-03-03, reporting said U.S. officials and organizations such as Health-ISAC were monitoring for possible spillover threats from the Iran-linked and pro-Russia-aligned campaign activity. Analysts warned that smaller U.S. critical infrastructure operators could face limited but high-visibility attacks.
By 2026-03-03, researchers said pro-Russia threat actors and Iran-linked groups had formed a loose coalition under the #OpIsrael campaign following U.S. and Israeli bombing on Iran. Reported activity included DDoS attacks, claimed breaches, leaked CCTV footage, SQL injection, and data leaks against Israeli targets.
Reporting published on 2026-04-23 said Iran-linked actors carried out a wiper attack against Stryker in March 2026 as part of increasingly destructive operations. The incident was cited alongside broader researcher observations that Iran-nexus groups were refining attacks against critical infrastructure and related targets.
In March 2026, the pro-Iran group Ababil of Minab claimed responsibility for intruding into the Los Angeles County Metropolitan Transportation Authority. LA Metro said it detected unauthorized activity and shut down access to parts of its network, though bus and rail operations were not affected and the group’s claims remained unverified.
By 2026, U.S. Treasury attribution linked CyberAv3ngers to six officials from the Islamic Revolutionary Guard Corps Cyber-Electronic Command. This shifted the narrative from nominal hacktivism toward direct Iranian state involvement.
On 2025-06-30, CISA, the FBI, DC3, and NSA issued a joint statement warning about potential targeted cyber activity by Iran against U.S. critical infrastructure. The statement marked an official U.S. government response to the threat environment.
During the June 2025 Israel-Iran conflict, analysis of Telegram activity reportedly showed coordinated mobilization among more than 178 hacktivist and proxy groups aligned with Iranian military developments. The activity suggested a broader ecosystem of aligned cyber actors rather than isolated independent groups.
In 2023, the CyberAv3ngers group conducted intrusions affecting U.S. water and wastewater systems. The activity was initially presented as pro-Palestinian hacktivism and highlighted the risk to industrial control and operational technology environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
25 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemalware.news
Open sourcenextgov.com
Open sourcetheguardian.com
Open sourcecisa.gov
Open sourcensa.gov
Open sourcecisa.gov
Open sourcepolitico.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.