Iran-linked threat actors tied to MOIS and IRGC-IO attempted a series of disruptive cyberattacks during the broader Iran conflict, including efforts to compromise internet-exposed programmable logic controllers in U.S. water systems, deploy a wiper against a U.S. healthcare company, and breach the email server of Albania’s parliament. The operations were presented by Iranian actors as strikes on critical infrastructure and public institutions across the United States, Israel, and Gulf states.
Reporting assessing the campaign says the attacks caused limited real-world damage and suggests Iran’s offensive cyber capacity may have been weakened by U.S. and Israeli cyber and kinetic pressure. The assessment concludes that while Iranian activity remains a resilience concern for operators of critical services, Russia still represents the more significant hybrid-warfare cyber threat to Europe, particularly if the war in Ukraine further deteriorates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Iranian-linked actors reportedly attacked the email server of Albania’s parliament. The operation is presented as part of a broader campaign of disruptive but largely low-impact activity.
The sources report deployment of a wiper malware attack against a U.S. healthcare company by Iranian-linked actors. The attack is described as disruptive but ultimately limited in impact.
Threat actors linked to Iran’s MOIS and IRGC-IO reportedly attempted to compromise internet-exposed programmable logic controllers used in U.S. water supply systems. The reporting says the operation was framed as a critical infrastructure strike but did not produce meaningful real-world impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.