Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Iranian-Aligned Cyber Mobilization (TL-2026-0183), also tracked as Operation Epic Fury Cyber Response, is a critical-severity ICS/SCADA threat, first published 2026-03-06. It is attributed to Cyber Av3ngers (Iran) with high confidence, affects Unitronics Vision Series PLCs/HMIs, maps to 35 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-0183
- Threat ID
- TL-2026-0183
- Also known as
- Operation Epic Fury Cyber Response, Iranian ICS Mobilization 2026, Electronic Operations Room Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- 2026-03-06
- Last reviewed
- 2026-03-06
- Attribution
- Cyber Av3ngers
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- water-wastewater, energy, oil-gas, manufacturing, telecommunications, government, healthcare, financial, defense, aviation, maritime
- Target regions
- North America, Middle East, Europe, Gulf Cooperation Council
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Iranian-Aligned Cyber Mobilization
Malware and tooling: Archer RAT, DistTrack, Handala Wiper (Hatef/Hamsa), IOCONTROL, TRITON/TRISIS, Tsundere Botnet - S9034, MQTT (ports 1883/8883)
Following the February 28, 2026 US-Israel strikes on Iran (Operation Epic Fury), more than 60 Iranian-aligned cyber groups mobilized within hours, forming an Electronic Operations Room on Telegram to coordinate retaliatory attacks against US critical infrastructure. Key threat actors include CyberAv3ngers (IOCONTROL malware, 75+ US ICS devices compromised), APT33/Elfin (TRITON/TRISIS capability, US energy sector targeting), MuddyWater/MERCURY (RustyWater 2026 Rust-based RAT), and APT34/OilRig. AI tools including ChatGPT have been abused for ICS/SCADA reconnaissance, sharply lowering the barrier to targeting internet-exposed industrial systems across US water, energy, and oil/gas sectors.
How Iranian-Aligned Cyber Mobilization works
Iranian-Aligned Cyber Mobilization Against US Critical Infrastructure ICS/SCADA Systems
STRATEGIC CONTEXT
On February 28, 2026, the United States in coordination with Israel launched Operation Epic Fury — a large-scale military air campaign against Iran that killed Supreme Leader Ayatollah Ali Khamenei along with several high-ranking Iranian officials. Within hours, more than 60 Iranian-aligned hacktivist and state-sponsored cyber groups activated, forming an Electronic Operations Room on Telegram to coordinate retaliatory cyber operations. Between February 28 and March 1, over 150 hacktivist incidents were claimed across open channels, targeting government, financial, aviation, telecom, and critical infrastructure in the US, Israel, and Gulf Cooperation Council (GCC) countries.
THREAT ACTOR LANDSCAPE
This campaign involves a layered threat actor ecosystem spanning Tier 1 nation-state APTs and Tier 2 state-aligned hacktivist groups:
Tier 1 — Nation-State APTs: - APT33/Elfin (Peach Sandstorm, IRGC-affiliated): Targeting US electric utilities and oil/gas since 2013. Demonstrated TRITON/TRISIS capability for Safety Instrumented System attacks. In 2025, sharply increased credential harvesting and OT network mapping against US energy companies. - APT34/OilRig (MOIS-affiliated): Long-dwell covert access specialists in the energy sector. Known for patient lateral movement and data exfiltration from high-value targets. - MuddyWater/MERCURY (Mango Sandstorm, MOIS-affiliated): Deployed RustyWater — a new Rust-based RAT in early 2026 — targeting diplomatic, maritime, financial, and telecom entities. Features position-independent XOR encryption, 25+ AV/EDR evasion checks, process injection via explorer.exe hollowing, and HTTP-based C2 with triple-layer encoding (JSON > Base64 > XOR). Also deploying Dindoor backdoor leveraging Deno JavaScript runtime. - Charming Kitten/APT35 (IRGC-IO): Intelligence collection feeding IRGC targeting operations, providing reconnaissance data for kinetic and cyber operations.
Tier 2 — State-Aligned Groups: - CyberAv3ngers/BAUXITE (IRGC-CEC): The most operationally active ICS-targeting group. Developed IOCONTROL — a custom Linux-based IoT/OT malware using MQTT for C2, DNS-over-HTTPS via Cloudflare for resolution, and AES-256-CBC encryption. CISA confirmed 75+ US ICS devices compromised (34+ in water/wastewater sector). Actively abused ChatGPT for ICS reconnaissance including Shodan queries, default credential enumeration, Modbus TCP/IP client creation, and bash script obfuscation. - Handala Hack Team (MOIS-aligned via Void Manticore): Deploys custom wiper malware (Hatef for Windows, Hamsa for Linux) with multi-stage delivery chains including NSIS installers, AutoIT scripts, and BYOVD exploitation. Claimed attacks against Israeli energy companies and Jordanian gas stations post-escalation. - Additional groups: FAD Team (SCADA/PLC wiper attacks), Dark Storm Team/MRHELL112 (DDoS/ransomware), Cyber Islamic Resistance (DDoS/wiper coordination), Evil Markhors (credential harvesting), 313 Team (DDoS), DieNet (DDoS).
MALWARE ARSENAL
IOCONTROL: Custom Iranian IoT/OT cyberweapon targeting Unitronics, D-Link, Hikvision, Red Lion, Orpak, Phoenix Contact, Teltonika, and Gasboy devices. Uses MQTT protocol (ports 1883/8883) for C2 communication, DNS-over-HTTPS via Cloudflare (1.1.1.1) for domain resolution, AES-256-CBC encryption, and modified UPX packing. Persists via RC scripts (/etc/rc3.d/S93InitSystemd.sh). Supports arbitrary command execution, port scanning, self-deletion, and device information exfiltration.
TRITON/TRISIS: Industrial Safety Instrumented System (SIS) targeting malware first deployed in 2017 against a Saudi petrochemical facility. Represents the most dangerous ICS-specific capability in the Iranian arsenal — designed to cause physical destruction by disabling safety systems.
Shamoon: Destructive disk wiper that destroyed 30,000 Saudi Aramco endpoints in 2012. Remains a template for Iranian destructive operations.
RustyWater: MuddyWater's 2026 Rust-based RAT delivered via spear-phishing with malicious Word documents. Features anti-analysis (VEH registration), 25+ AV evasion checks, registry persistence (CurrentVersion\Run), HTTP-based C2 with reqwest/0.12.23, process hollowing of explorer.exe, and asynchronous operation via Rust tokio runtime.
Handala Wiper: Multi-stage wiper delivered via phishing PDFs, using NSIS > batch > AutoIT > shellcode chain. Exploits vulnerable driver (ListOpenedFileDrv) via BYOVD for privilege escalation. Overwrites files with 4,096 bytes of random data.
AI-ASSISTED RECONNAISSANCE
OpenAI confirmed in October 2024 that CyberAv3ngers abused ChatGPT for ICS reconnaissance, including: generating Shodan queries for exposed industrial devices, enumerating default credentials for Tridium Niagara and Hirschmann devices, creating Modbus TCP/IP clients programmatically, developing network scanning scripts, obfuscating bash exploitation scripts, and querying industrial router geographic deployment patterns. This represents a significant lowering of the barrier to ICS/SCADA targeting.
ATTACK SURFACE
The ICS/SCADA attack surface has expanded dramatically: OT/ICS internet exposure increased 35% year-over-year in H1 2025, Unitronics port 20256 exposure surged 160% despite CISA advisories, and over 40,000 internet-exposed control systems are documented globally. CyberAv3ngers specifically target devices with default credentials (Unitronics default password "1111") and unauthenticated web interfaces.
TARGETED SYSTEMS
Primary targets include: Unitronics Vision Series PLCs (port 20256), Siemens SIMATIC CP 343-1 (unauthenticated web interfaces), Tridium Niagara devices, Hirschmann RS industrial routers, Orpak/Gasboy fuel management systems, and generic Modbus TCP (port 502) devices. Affected sectors: US water/wastewater, electric utilities, oil/gas, manufacturing, telecommunications, healthcare, and government.
ASSESSMENT
This represents the most significant coordinated Iranian cyber campaign against US critical infrastructure to date. The combination of Tier 1 APTs with pre-positioned access, Tier 2 groups with demonstrated ICS exploitation capability, AI-lowered barriers to reconnaissance, and an expanding attack surface of exposed industrial systems creates a high-confidence assessment of imminent destructive cyber operations against US ICS/SCADA infrastructure. The Electronic Operations Room coordination mechanism enables rapid target handoff between reconnaissance groups and exploitation teams.
---
**Revalidated on 2026-03-12**
Six days after initial publication, this threat has escalated from theoretical mobilization to confirmed destructive operations against major US enterprises. The Handala Hack wiper attack on Stryker Corporation on March 11, 2026 represents a watershed moment — the first confirmed destructive cyberattack by an Iranian-linked actor against a major US company since Operation Epic Fury began. Handala claims 50TB of exfiltrated data and 200,000+ wiped systems across 79 countries, causing total operational shutdown of a $100B+ medical technology company. This attack validates the original assessment that Iranian state-aligned groups would progress from DDoS and defacement to destructive wiper operations.
Simultaneously, Symantec's March 5 disclosure of MuddyWater's pre-positioned access inside a US bank, US airport, and defense/aerospace software company via the novel Dindoor backdoor confirms that Tier 1 APTs had established footholds inside US critical infrastructure weeks before the kinetic strikes began. The Dindoor backdoor leverages the Deno JavaScript/TypeScript runtime for command execution, while the companion Fakeset Python backdoor was found on airport networks — both signed with certificates (Amy Cherne, Donald Gay) previously linked to MuddyWater. Data exfiltration attempts using Rclone to Wasabi cloud storage were observed at the software company.
The US government response has intensified significantly. CISA, FBI, DC3, and NSA published a joint statement specifically addressing Iranian cyber threats to US critical infrastructure. The US intelligence community issued private warnings the week of March 10 to companies and agencies, with DHS specifically warning about 'ongoing claims and calls for cyber attacks targeting US entities by Iranian-aligned groups' against the financial services sector. However, CISA is critically under-resourced, operating at roughly 38% staffing capacity with its temporary director reassigned.
Proofpoint confirmed TA453 (Charming Kitten/APT42) conducted credential phishing against a US thinktank on March 8, demonstrating that IRGC intelligence collection operations persist despite Iran's near-total internet blackout (1-4% connectivity since Feb 28). Halcyon's assessment is that Iran is 'actively weighing destructive cyber operations as a retaliatory vector,' with MuddyWater conducting a structured offensive designated Operation Olalampo targeting the META region.
The Russia-Iran hacktivist convergence has materialized as predicted: NoName057(16) teamed with Iranian hacktivists on March 2 to target Israeli defense organizations including Elbit Systems, and Z-Pentest claimed ICS/SCADA compromises at multiple US entities. SOCRadar recorded over 600 distinct cyberattack claims across 100+ Telegram channels within 15 days. The Dragos 2026 OT Cybersecurity Year in Review confirms BAUXITE (CyberAv3ngers) deployed two custom wiper variants against Israeli targets during the June 2025 conflict — establishing a clear escalation pattern now extended to US targets. CloudSEK documented 182,200 internet-exposed industrial assets in the US, and CSIS analysis characterizes Iran's cyber ecosystem as deliberately designed to 'deputize hacktivist proxies in state actions without state attribution,' with the current activation representing the largest-scale deployment of this architecture in history.
Threat status remains CRITICAL with active exploitation confirmed. The progression from hacktivist DDoS to APT pre-positioning to confirmed destructive wiper attacks on US enterprises validates the highest assessment level.
MITRE ATT&CK techniques used in TL-2026-0183
collection
exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
discovery
T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1106 Native API
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1571 Non-Standard Port; T1573 Encrypted Channel
credential-access
initial-access
T1190 Exploit Public-Facing Application; T1566 Phishing
impact
T1485 Data Destruction; T1491 Defacement; T1499 Endpoint Denial of Service; T1531 Account Access Removal; T1561 Disk Wipe; T1565 Data Manipulation
persistence
T1547 Boot or Logon Autostart Execution
lateral-movement
resource-development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1592 Gather Victim Host Information; T1595 Active Scanning
Affected products and versions in Iranian-Aligned Cyber Mobilization
- Unitronics — Vision Series PLCs/HMIs
Vulnerable versions: All versions with default credentials
Fixed in: VisiLogic 9.9.00+ with credential changes - Siemens — SIMATIC CP 343-1
Vulnerable versions: Versions with unauthenticated web interfaces - Tridium — Niagara Framework
Vulnerable versions: Versions with default credentials - Hirschmann — RS Industrial Routers
Vulnerable versions: Versions with default credentials - Orpak — Fuel Management Systems
Vulnerable versions: IOCONTROL-targeted versions - Gasboy — Fuel Management Systems
Vulnerable versions: IOCONTROL-targeted versions - D-Link — Industrial Routers
Vulnerable versions: IOCONTROL-targeted models - Hikvision — IP Cameras (OT environments)
Vulnerable versions: IOCONTROL-targeted models - Red Lion — Industrial Devices
Vulnerable versions: IOCONTROL-targeted models - Phoenix Contact — Industrial Controllers
Vulnerable versions: IOCONTROL-targeted models
Remediation for Iranian-Aligned Cyber Mobilization
Patches
- Upgrade Unitronics VisiLogic software to version 9.9.00 or later
- Update all Unitronics Vision Series PLC/HMI firmware to newest version
- Apply latest Siemens SIMATIC firmware updates
- Patch all internet-facing devices per CISA Known Exploited Vulnerabilities catalog
Immediate actions
- Remove ICS/SCADA management interfaces from public internet immediately
- Change all default credentials on Unitronics PLCs (default password 1111)
- Block ICS protocol ports (20256, 502, 102, 44818, 1911, 47808) from internet-facing access
- Implement geographic IP blocking from Iran and known proxy regions
- Monitor for MQTT traffic on ports 1883/8883 to unexpected destinations
- Block DNS-over-HTTPS to 1.1.1.1 from OT networks
- Verify no IOCONTROL persistence at /etc/rc3.d/S93InitSystemd.sh on Linux ICS devices
- Hunt for RustyWater persistence at SOFTWARE\Microsoft\Windows\CurrentVersion\Run pointing to CertificationKit.ini
Workarounds
- Disconnect PLCs from public-facing internet if patching is not immediately possible
- Enable password protection on all Unitronics upload/download functions
- Implement allowlisting for Modbus TCP connections on port 502
- Monitor Shodan and Censys for organizational ICS device exposure
Longer-term hardening
- Deploy network segmentation using Purdue Model for ICS/OT environments
- Implement multifactor authentication for all OT network access
- Deploy VPN/gateway solutions in front of all PLCs and HMIs
- Establish air-gapped offline backups of critical ICS configurations and ladder logic
- Deploy ICS-aware intrusion detection (Claroty, Dragos, Nozomi) on OT networks
- Conduct periodic inventory of internet-accessible ICS devices
- Implement out-of-band verification for all OT network change requests
- Train operators on social engineering and spear-phishing targeting ICS personnel
Weaknesses (CWE) in Iranian-Aligned Cyber Mobilization
CWE-798, CWE-287, CWE-306, CWE-1188
Timeline of Iranian-Aligned Cyber Mobilization
Showing the 20 most recent tracked events.
- CyberAv3ngers compromise Aliquippa Municipal Water Authority (Pennsylvania) via Unitronics PLC default credentials — first confirmed US water utility compromise
- CISA publishes advisory AA23-335A documenting IRGC-affiliated exploitation of Unitronics PLCs across US critical infrastructure — confirms 75+ devices compromised
- OpenAI confirms CyberAv3ngers used ChatGPT for ICS reconnaissance — Shodan queries, default credential enumeration, Modbus TCP/IP client creation
- Claroty Team82 publishes comprehensive IOCONTROL malware analysis — reveals MQTT C2, AES-256-CBC encryption, DNS-over-HTTPS, targeting of 10+ device vendors
- MuddyWater deploys RustyWater Rust-based RAT via spear-phishing targeting diplomatic, maritime, financial, and telecom entities across Middle East
- H1 2025 data shows OT/ICS internet exposure increased 35% year-over-year with 40,000+ exposed control systems globally — Unitronics port 20256 exposure surges 160%
- Dragos publishes 2026 OT Cybersecurity Year in Review confirming BAUXITE deployed two custom wiper malware variants against Israeli targets during June 2025 Iran-Israel conflict, and tracks three new OT threat groups with adversaries progressing from reconnaissance to operational disruption of industrial control systems [Source: https://www.dragos.com/blog/dragos-2026-ot-cybersecurity-year-in-review]
- US-Israel launch Operation Epic Fury against Iran — Supreme Leader Khamenei killed. 60+ Iranian-aligned hacktivist groups activate within hours, Electronic Operations Room formed on Telegram
- Over 150 hacktivist incidents claimed in 72 hours — DDoS, website defacement, and data breach operations targeting US, Israel, and GCC government, financial, aviation, and critical infrastructure
- Pro-Russian hacktivist group NoName057(16) coordinates with Iranian hacktivists to jointly target Israeli defense and municipal organizations including defense contractor Elbit Systems; Z-Pentest claims compromise of multiple US-based ICS/SCADA entities [Source: https://www.axios.com/2026/03/11/iran-war-trump-israel-ai-cyberattack]
- CCCS, Unit 42, Arctic Wolf, Sophos, BeyondTrust issue advisories warning of heightened Iranian cyber threat to critical infrastructure following escalation
- CISA, FBI, DC3, and NSA publish joint statement on potential targeted cyber activity against US critical infrastructure by Iran, urging increased vigilance though noting no confirmed coordinated campaign yet attributed to Iran [Source: https://www.cisa.gov/news-events/news/joint-statement-cisa-fbi-dc3-and-nsa-potential-targeted-cyber-activity-against-us-critical]
- CNBC reports CISA operating at approximately 38% staffing capacity with temporary director reassigned; FBI issues reminder to critical infrastructure organizations to implement mitigations from joint fact sheet on Iranian-affiliated cyber actors [Source: https://www.cnbc.com/2026/03/03/iran-cisa-cybersecurity-war-threat.html]
- Symantec/Broadcom discloses MuddyWater (Seedworm) pre-positioned Dindoor backdoor (Deno-based) and Fakeset Python backdoor inside US bank, US airport, US/Canadian NGOs, and Israeli operations of US defense/aerospace software company — campaign began early February 2026 [Source: https://www.security.com/threat-intelligence/iran-cyber-threat-activity-us]
- CloudSEK publishes comprehensive analysis documenting AI-assisted ICS reconnaissance, 60+ group mobilization, and threat to US water/energy/oil-gas critical infrastructure
- Proofpoint observes TA453 (Charming Kitten/APT42, IRGC-IO) credential phishing campaign against US thinktank, confirming Iranian intelligence collection operations active despite near-total domestic internet outage [Source: https://www.proofpoint.com/us/blog/threat-insight/iran-conflict-drives-heightened-espionage-activity-against-middle-east-targets]
- US intelligence community issues flurry of private warnings to American companies and government agencies urging vigilance against Iranian cyber retaliation; DHS warns of heightened threat environment following killing of Supreme Leader Khamenei [Source: https://www.cnn.com/2026/03/10/politics/us-intel-warning-retaliatory-attacks-iran]
- Axios and NPR report AI-fueled cyberattacks escalating in Iran conflict, with cyberwarfare ''coming out of the shadows'' as Iran leverages cyber operations due to lacking ''symmetric conventional response options against the United States and Israel'' [Source: https://www.axios.com/2026/03/11/iran-war-trump-israel-ai-cyberattack]
- Handala Hack (MOIS-linked via Void Manticore) executes destructive wiper attack on Stryker Corporation (NYSE: SYK, $100B+ US medical device manufacturer), claiming exfiltration of 50TB data before wiping 200,000+ systems across 79 countries — first confirmed destructive Iranian-linked attack on a major US enterprise post-Operation Epic Fury [Source: https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/]
- As of 2026-05-29, this Iranian-aligned ICS/SCADA campaign remains ACTIVE and escalating: CISA's six-agency advisory AA26-097A (Apr 7, 2026) confirmed PLC compromise, operational disruption, and financial loss at US critical-infrastructure orgs. CyberAv3ngers, APT33, and MuddyWater are still operating (now exploiting CVE-2021-22681 on internet-facing PLCs), with CSIS calling the trend irreversible and no evidence of capability disruption.
Sources cited for Iranian-Aligned Cyber Mobilization
- CloudSEK — AI, the Iran-US Conflict, and the Threat to US Critical Infrastructure
- CISA Advisory AA23-335A — IRGC-Affiliated Cyber Actors Exploit PLCs
- Palo Alto Unit 42 — Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran
- Canadian Centre for Cyber Security — Iranian Cyber Threat Response to US/Israel Strikes
- Claroty Team82 — Inside a New OT/IoT Cyberweapon: IOCONTROL
- CloudSEK — Reborn in Rust: MuddyWater Evolves Tooling with RustyWater Implant
- Splunk — Handala Wiper Threat Analysis and Detections
- CNBC — The Lead US Cyber Agency Is Stretched Thin as Iran Hacking Threat Escalates
- Nextgov — Intelligence Firms Watch for Uptick in Iran Cyber Activity After US-Israel Strikes
- Fortune — Iran Could Use AI to Accelerate Cyberattacks on US and Israeli Critical Infrastructure
- CloudSEK — Middle East Escalation Situation Report
- Arctic Wolf — Heightened Cyber Risk Following February 2026 US/Israel-Iran Escalation
- MITRE ATT&CK — APT33 (G0064)
- CISA — Iran Threat Overview and Advisories
- SOCRadar — Cyber Reflections: US-Israel-Iran War
Threats related to Iranian-Aligned Cyber Mobilization
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)
- Boggy Serpens (MuddyWater) AI-Enhanced Cyberespionage Campaign Deploying Nuso, LampoRAT, BlackBeard, Phoenix, and UDPGangster Malware
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
Detection coverage for TL-2026-0183
As of 2026-03-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0183 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.