Iranian cyber operations historically followed a dual-track doctrine. The first track focused on espionage, aimed at acquiring intellectual property, military blueprints, and dissident intelligence to ensure regime survival and economic resilience under sanctions. The second track focused on deterrence, utilizing disruptive wiper attacks and critical infrastructure probing to signal the costs of conflict to adversaries.
However, in 2025, these tracks increasingly converged. Intelligence collection operations against the U.S. defense industrial base, conducted by groups like APT33, were not solely for IP theft but also for “preparation of the environment”—identifying chokepoints in logistics and satellite communications that could be disrupted in a hot war. Similarly, the “hacktivist” attacks on Israeli and U.S. water systems by CyberAv3ngers were not random acts of vandalism but calculated psychological operations designed to demonstrate the reach of the Islamic Revolutionary Guard Corps (IRGC) into the daily lives of Western populations.
Inside Iran’s APT Network: Profiling the Most Active Iranian State‑Linked Threat Actors
FalconFeeds.io
https://falconfeeds.io/blogs/inside-irans-apt-network-most-active-iranian-state-linked-threat-actors-2024-2025/
The Industrialization of Iranian Cyber Operations
The landscape of Iranian state-sponsored cyber operations has undergone a profound transformation between 2024 and 2025. Once characterized by noisy, destructive wiper attacks and relatively unsophisticated coercion attempts, the Iranian cyber apparatus has matured into a tier-one adversary capable of sustained, stealthy espionage and precise kinetic disruption. This evolution is not merely technical but organizational; intelligence gathered throughout late 2024 and 2025 indicates a concerted effort by the Islamic Republic to bureaucratize its cyber forces, integrating them deeply into the state’s military and intelligence hierarchies while simultaneously diversifying their tactical portfolios to include advanced cloud evasion, supply chain interdiction, and aggressive “hacktivist” psychological warfare.
This blog offers a comprehensive operational profile of the most active Iranian Advanced Persistent Threat (APT) groups during this period: APT33 (Peach Sandstorm), APT34 (OilRig), APT35 (Charming Kitten), MuddyWater (Mango Sandstorm), and the MOIS-linked psychological warfare unit Handala Hack (Banished Kitten). It also analyzes the emerging threat of state-aligned hacktivist fronts such as CyberAv3ngers. The analysis draws upon forensic data, campaign telemetry, and internal documents leaked in September 2025 to reconstruct the strategic doctrine driving Tehran’s digital offensive.
Three primary macro-trends define the 2024–2025 operational window. First, the weaponization of identity and cloud infrastructure has become the dominant initial access vector, with groups like APT33 pivoting from vulnerability exploitation to industrial-scale password spraying and Azure-native command and control (C2). Second, the corporatization of espionage has been laid bare by leaks revealing that groups like APT35 operate under strict quotas and performance metrics, functioning more like government contractors than loose hacker collectives. Third, the convergence of espionage and kinetic intent is visible in the targeting of U.S. and Israeli critical infrastructure—specifically water systems and ports—where the objective often blurs the line between intelligence preparation of the battlefield and active signaling of retaliatory capability.
The following sections detail the organizational structures, technical tradecraft, and campaign histories of these actors, providing a strategic baseline for defense industrial base (DIB), government, and critical infrastructure stakeholders.
Strategic Context: The Geopolitics of the “War Between Wars”
To fully comprehend the tactical shifts of Iranian APTs, one must situate them within the broader geopolitical strategy of the Islamic Republic. The cyber domain serves as Iran’s primary vector for asymmetric power projection, allowing Tehran to counter superior conventional military adversaries—principally the United States and Israel—while maintaining a threshold of plausibility and deniability. The period of 2024 and 2025 was marked by heightened regional instability, including the lingering fallout of the Gaza conflict and shifting alliances in the Gulf, which directly influenced cyber targeting priorities.
The Dual-Track Doctrine: Espionage and Deterrence
Iranian cyber operations historically followed a dual-track doctrine. The first track focused on espionage, aimed at acquiring intellectual property, military blueprints, and dissident intelligence to ensure regime survival and economic resilience under sanctions. The second track focused on deterrence, utilizing disruptive wiper attacks and critical infrastructure probing to signal the costs of conflict to adversaries.
However, in 2025, these tracks increasingly converged. Intelligence collection operations against the U.S. defense industrial base, conducted by groups like APT33, were not solely for IP theft but also for “preparation of the environment”—identifying chokepoints in logistics and satellite communications that could be disrupted in a hot war. Similarly, the “hacktivist” attacks on Israeli and U.S. water systems by CyberAv3ngers were not random acts of vandalism but calculated psychological operations designed to demonstrate the reach of the Islamic Revolutionary Guard Corps (IRGC) into the daily lives of Western populations.
米当局、水道施設へのサイバー攻撃が急増と警告 イラン系ハッカーか
by A.J. Vicens
https://jp.reuters.com/world/security/TBATYQBWRBN33FMC5JM7JLDYGQ-2026-07-31/
米国土安全保障省サイバー・インフラ安全局(CISA)や連邦捜査局(FBI)などの当局は30日、上下水道施設の維持・管理に使われているシステムを標的としたサイバー攻撃が大幅に増えていると警告した。またこの分野の運営事業者に対し、システムをできるだけ早くインターネットから切り離すよう要請した。
米国の水道施設を巡っては中西部ミネソタ州のIT当局が28日、州内で26、27両日に30を超える地域水道施設のシステムが「組織的なサイバー攻撃」の標的となったと公表したばかりだった。
FBIは30日夜、少なくとも7州の上下水道事業者がサイバー攻撃を受けたと報告があり、一部では水圧の低下や浸水が発生するなど「水道事業の運営に支障を来した」と説明した。
米紙ニューヨーク・タイムズは30日、ミネソタ州のシステムに対するサイバー攻撃はイランと関連のあるハッカーが関与している可能性が高いと報じた。イラン政府の当局者は、コメント要請に直ちには回答しなかった。
トランプ米政権はイランとの対立を激化させており、両国はミサイル攻撃の応酬を繰り広げている。
米国の水道施設を標的としたイラン関連のサイバー攻撃は、2月末の米国とイスラエルによるイラン攻撃に端を発した中東紛争の前から起きていた。ただ、3月には医療サービス企業のストライカーや、西部カリフォルニア州のロサンゼルス郡都市圏交通局といった米国内の組織に対してさまざまなグループによるサイバー攻撃が相次いだ。
複数の当局によると、ミネソタ州でのサイバー攻撃は水の安全性に脅威を与えるものではなかったものの、一部のシステムが停止し、手動で再起動する必要があった。標的にされたのは、システムが水道施設を遠隔から監視・制御するために使うプログラマブル・ロジック・コントローラ(PLC)や、事業者がそれらを管理するために用いているコンピューター画面に関わるものだった。
ミネソタ州のジョン・イスラエル最高情報セキュリティー責任者は、同州が「連邦政府に関連情報を提供しており、連邦政府がより広範な国家の文脈で評価するとともに、特定のグループによる犯行なのかを特定するための調査を主導している」とコメントした。
CISAが30日発表した内容によると、ハッカーがパスワードを変更して運営事業者のアクセスを遮断し、特定のデバイスをネットワークから切り離したケースがあり、事業者が「水の煮沸勧告や手動操作の継続」に対応することを余儀なくされた。
元FBIサイバーセキュリティー担当高官のシンシア・カイザー氏はロイターに対し、ミネソタ州でのサイバー攻撃はCISAやFBI、国家安全保障局(NSA)などの政府機関が4月に勧告したように、イランと関連したハッカーによるPLCや、他の重要インフラ技術に対する過去の標的型サイバー攻撃の延長線上にある可能性が極めて高いとの見解を示した。
この勧告は7月22日に更新され、当初の対象よりも広範なデバイスが含まれ、ハッカーが抱える最新技術や活動が盛り込まれた。
カイザー氏は「新たな勧告が出されたという事実は、攻撃の拡大か、新たな技術の詳細、または活動の再開のいずれかがあったことを示唆しており、恐らくこれら全ての要素が組み合わさっているのだろう」と話した。
(sk)
IT のセキュリティを万全にしても、IOT のほうから破られる。イランだけでなく、ロシアも、北朝鮮も、狙うところは同じ。コンピュータ内臓の IOT 端末を狙われたら、防ぐ手立ては インターネットから Disconnect するしかない。担当者たちは、悩ましいに違いなく、インターネットから Disconnect すれば、本来の機能が使えなくなり、だからといって Connect すればハッキングされる。どうしたらいいのやら。