Iranian state-linked operations are increasingly using artificial intelligence as a force multiplier across cyber intrusions, influence activity, and broader hybrid warfare. Reporting on activity through the first half of 2026 says Tehran applied generative AI and large language models to speed up spearphishing, reconnaissance, malware development, and social engineering, while preserving familiar tradecraft such as credential theft, wipers, and hack-and-leak operations. The activity aligns with broader threat intelligence tracking that shows adversaries integrating AI into established workflows through experimentation, distillation, and operational deployment rather than relying on wholly new attack methods.
The reporting also ties Iran’s AI-enabled activity to established intrusion sets and regional operations, including campaigns attributed to MuddyWater, and warns that the technology is helping scale information operations, domestic repression, and potentially military support functions. Analysts say foreign support and technology transfer from Russia and China are contributing to this progress, raising concern that AI-enhanced Iranian campaigns will continue to target Western and regional critical infrastructure, vital industries, and public trust with faster, more efficient cyber and influence operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Recorded Future published an assessment that Iran used AI between January and June 2026 to accelerate existing cyber, influence, and repression tactics during the 2026 conflict, rather than to create fundamentally new capabilities.
Google Threat Intelligence Group published research describing threat actors' experimentation with and integration of AI for adversarial use, including distillation and operational adoption patterns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcerecordedfuture.com
Open sourcecloud.google.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.