Check Point Research reported that Iranian-linked operators conducted targeted malware attacks against Iraqi government infrastructure, indicating a focused espionage or disruptive campaign against state networks. The activity was aimed at government entities in Iraq and was attributed to Iranian threat actors based on the researchers’ investigation.
The report describes a deliberate intrusion set involving malware used against Iraqi public-sector systems, underscoring ongoing cyber operations in the region in which nation-state-aligned groups target neighboring governments for intelligence collection and strategic access. The findings add to evidence that Iraqi government networks remain a priority target in broader Iran-linked cyber activity.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point Research released a detailed technical analysis of the WezRat malware. This added new technical detail to the previously disclosed campaign involving Iranian malware activity targeting Iraqi government infrastructure.
Check Point Research published findings on a targeted campaign described as Iranian malware attacks against Iraqi government infrastructure. The reference indicates public disclosure of the activity but provides no additional incident details in the supplied content.
Bitdefender published a technical blog post analyzing BellaCiao, described as an Iranian malware strain. This represents an earlier public disclosure and technical examination separate from the later Check Point reporting on WezRat and attacks on Iraqi government infrastructure.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourceresearch.checkpoint.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.