Iranian Cyber Operations (FalconFeeds.io)

Iranian cyber operations historically followed a dual-track doctrine. The first track focused on espionage, aimed at acquiring intellectual property, military blueprints, and dissident intelligence to ensure regime survival and economic resilience under sanctions. The second track focused on deterrence, utilizing disruptive wiper attacks and critical infrastructure probing to signal the costs of conflict to adversaries.
However, in 2025, these tracks increasingly converged. Intelligence collection operations against the U.S. defense industrial base, conducted by groups like APT33, were not solely for IP theft but also for “preparation of the environment”—identifying chokepoints in logistics and satellite communications that could be disrupted in a hot war. Similarly, the “hacktivist” attacks on Israeli and U.S. water systems by CyberAv3ngers were not random acts of vandalism but calculated psychological operations designed to demonstrate the reach of the Islamic Revolutionary Guard Corps (IRGC) into the daily lives of Western populations.

Iranian Cyber Operations (FalconFeeds.io)」への3件のフィードバック

  1. phrh205455 投稿作成者

    Inside Iran’s APT Network: Profiling the Most Active Iranian State‑Linked Threat Actors

    FalconFeeds.io

    https://falconfeeds.io/blogs/inside-irans-apt-network-most-active-iranian-state-linked-threat-actors-2024-2025/

    The Industrialization of Iranian Cyber Operations

    The landscape of Iranian state-sponsored cyber operations has undergone a profound transformation between 2024 and 2025. Once characterized by noisy, destructive wiper attacks and relatively unsophisticated coercion attempts, the Iranian cyber apparatus has matured into a tier-one adversary capable of sustained, stealthy espionage and precise kinetic disruption. This evolution is not merely technical but organizational; intelligence gathered throughout late 2024 and 2025 indicates a concerted effort by the Islamic Republic to bureaucratize its cyber forces, integrating them deeply into the state’s military and intelligence hierarchies while simultaneously diversifying their tactical portfolios to include advanced cloud evasion, supply chain interdiction, and aggressive “hacktivist” psychological warfare.

    This blog offers a comprehensive operational profile of the most active Iranian Advanced Persistent Threat (APT) groups during this period: APT33 (Peach Sandstorm), APT34 (OilRig), APT35 (Charming Kitten), MuddyWater (Mango Sandstorm), and the MOIS-linked psychological warfare unit Handala Hack (Banished Kitten). It also analyzes the emerging threat of state-aligned hacktivist fronts such as CyberAv3ngers. The analysis draws upon forensic data, campaign telemetry, and internal documents leaked in September 2025 to reconstruct the strategic doctrine driving Tehran’s digital offensive.

    Three primary macro-trends define the 2024–2025 operational window. First, the weaponization of identity and cloud infrastructure has become the dominant initial access vector, with groups like APT33 pivoting from vulnerability exploitation to industrial-scale password spraying and Azure-native command and control (C2). Second, the corporatization of espionage has been laid bare by leaks revealing that groups like APT35 operate under strict quotas and performance metrics, functioning more like government contractors than loose hacker collectives. Third, the convergence of espionage and kinetic intent is visible in the targeting of U.S. and Israeli critical infrastructure—specifically water systems and ports—where the objective often blurs the line between intelligence preparation of the battlefield and active signaling of retaliatory capability.

    The following sections detail the organizational structures, technical tradecraft, and campaign histories of these actors, providing a strategic baseline for defense industrial base (DIB), government, and critical infrastructure stakeholders.

    Strategic Context: The Geopolitics of the “War Between Wars”

    To fully comprehend the tactical shifts of Iranian APTs, one must situate them within the broader geopolitical strategy of the Islamic Republic. The cyber domain serves as Iran’s primary vector for asymmetric power projection, allowing Tehran to counter superior conventional military adversaries—principally the United States and Israel—while maintaining a threshold of plausibility and deniability. The period of 2024 and 2025 was marked by heightened regional instability, including the lingering fallout of the Gaza conflict and shifting alliances in the Gulf, which directly influenced cyber targeting priorities.

    The Dual-Track Doctrine: Espionage and Deterrence

    Iranian cyber operations historically followed a dual-track doctrine. The first track focused on espionage, aimed at acquiring intellectual property, military blueprints, and dissident intelligence to ensure regime survival and economic resilience under sanctions. The second track focused on deterrence, utilizing disruptive wiper attacks and critical infrastructure probing to signal the costs of conflict to adversaries.

    However, in 2025, these tracks increasingly converged. Intelligence collection operations against the U.S. defense industrial base, conducted by groups like APT33, were not solely for IP theft but also for “preparation of the environment”—identifying chokepoints in logistics and satellite communications that could be disrupted in a hot war. Similarly, the “hacktivist” attacks on Israeli and U.S. water systems by CyberAv3ngers were not random acts of vandalism but calculated psychological operations designed to demonstrate the reach of the Islamic Revolutionary Guard Corps (IRGC) into the daily lives of Western populations.

    返信
  2. phrh205455 投稿作成者

    米当局、水道施設へのサイバー攻撃が急増と警告 イラン系ハッカーか

    by A.J. Vicens

    https://jp.reuters.com/world/security/TBATYQBWRBN33FMC5JM7JLDYGQ-2026-07-31/

    米国土安全保障省サイバー・インフラ安全局(CISA)や連邦捜査局(FBI)などの当局は30日、上下水道施設の維持・管理に使われているシステムを標的としたサイバー攻撃が大幅に増えていると警告した。またこの分野の運​営事業者に対し、システムをできるだけ早くインターネットから切り離すよう要請した。

    米国の水道‌施設を巡っては中西部ミネソタ州のIT当局が28日、州内で26、27両日に30を超える地域水道施設のシステムが「組織的なサイバー攻撃」の標的となったと公表したばかりだった。

    FBIは30日夜、少なくとも7州の上下水道事業者がサイバー攻撃を受けたと報告があり、一部では水圧の低下や浸水が発生するな​ど「水道事業の運営に支障を来した」と説明した。

    米紙ニューヨーク・タイムズは30日、ミネソタ州のシステムに対​するサイバー攻撃はイランと関連のあるハッカーが関与している可能性が高いと報じた。⁠イラン政府の当局者は、コメント要請に直ちには回答しなかった。

    トランプ米政権はイランとの対立を激化させて​おり、両国はミサイル攻撃の応酬を繰り広げている。

    米国の水道施設を標的としたイラン関連のサイバー攻撃は、2月末の​米国とイスラエルによるイラン攻撃に端を発した中東紛争の前から起きていた。ただ、3月には医療サービス企業のストライカーや、西部カリフォルニア州のロサンゼルス郡都市圏交通局といった米国内の組織に対してさまざまなグループによるサイバー攻撃が相次いだ。

    複数の​当局によると、ミネソタ州でのサイバー攻撃は水の安全性に脅威を与えるものではなかったものの、一部のシス​テムが停止し、手動で再起動する必要があった。標的にされたのは、システムが水道施設を遠隔から監視・制御するために使うプ‌ログラマ⁠ブル・ロジック・コントローラ(PLC)や、事業者がそれらを管理するために用いているコンピューター画面に関わるものだった。

    ミネソタ州のジョン・イスラエル最高情報セキュリティー責任者は、同州が「連邦政府に関連情報を提供しており、連邦政府がより広範な国家の文脈で評価するとともに、特定のグループによる犯行なのかを特定するための調​査を主導している」とコメント​した。

    CISAが30日発表した内容によ⁠ると、ハッカーがパスワードを変更して運営事業者のアクセスを遮断し、特定のデバイスをネットワークから切り離したケースがあり、事業者が「水の煮沸勧告や手動操作の​継続」に対応することを余儀なくされた。

    元FBIサイバーセキュリティー担当高官のシンシア・カ​イザー氏はロ⁠イターに対し、ミネソタ州でのサイバー攻撃はCISAやFBI、国家安全保障局(NSA)などの政府機関が4月に勧告したように、イランと関連したハッカーによるPLCや、他の重要インフラ技術に対する過去の標的型サイバー攻撃の延長線上にある可能性が極めて高いとの見解⁠を示した。

    この​勧告は7月22日に更新され、当初の対象よりも広範なデバイスが含まれ、ハッ​カーが抱える最新技術や活動が盛り込まれた。

    カイザー氏は「新たな勧告が出されたという事実は、攻撃の拡大か、新たな技術の詳細、または活動の​再開のいずれかがあったことを示唆しており、恐らくこれら全ての要素が組み合わさっているのだろう」と話した。

    返信
  3. phrh205455 投稿作成者

    (sk)

    IT のセキュリティを万全にしても、IOT のほうから破られる。イランだけでなく、ロシアも、北朝鮮も、狙うところは同じ。コンピュータ内臓の IOT 端末を狙われたら、防ぐ手立ては インターネットから Disconnect するしかない。担当者たちは、悩ましいに違いなく、インターネットから Disconnect すれば、本来の機能が使えなくなり、だからといって Connect すればハッキングされる。どうしたらいいのやら。

    返信

コメントを残す

メールアドレスが公開されることはありません。 が付いている欄は必須項目です