Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026) — Threadlinqs Intelligence
As of 2026-05-30, Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026) is a critical-severity ics scada threat attributed to Cyber Av3ngers (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-0183 · Severity: CRITICAL · Status: ACTIVE · Category: ICS_SCADA
Attribution: Cyber Av3ngers · Iran · DESTRUCTION
Following the February 28, 2026 US-Israel strikes on Iran (Operation Epic Fury), more than 60 Iranian-aligned cyber groups mobilized within hours, forming an Electronic Operations Room on Telegram to
Iranian-Aligned Cyber Mobilization Against US Critical Infrastructure ICS/SCADA Systems
STRATEGIC CONTEXT
On February 28, 2026, the United States in coordination with Israel launched Operation Epic Fury — a large-scale military air campaign against Iran that killed Supreme Leader Ayatollah Ali Khamenei along with several high-ranking Iranian officials. Within hours, more than 60 Iranian-aligned hacktivist and state-sponsored cyber groups activated, forming an Electronic Operations Room on Telegram to coordinate retaliatory cyber operations. Between February 28 and March 1, over 150 hacktivist incidents were claimed across open channels, targeting government, financial, aviation, telecom, and critical infrastructure in the US, Israel, and Gulf Cooperation Council (GCC) countries.
THREAT ACTOR LANDSCAPE
This campaign involves a layered threat actor ecosystem spanning Tier 1 nation-state APTs and Tier 2 state-aligned hacktivist groups:
Tier 1 — Nation-State APTs:
- APT33/Elfin (Peach Sandstorm, IRGC-affiliated): Targeting US electric utilities and oil/gas since 2013. Demonstrated TRITON/TRISIS capability for Safety Instrumented System attacks. In 2025, sharply increased credential harvesting and OT network mapping against US energy companies.
- APT34/OilRig (MOIS-affiliated): Long-dwell covert access specialists in the energy sector. Known for patient lateral movement and data exfiltration from high-value targets.
- MuddyWater/MERCURY (Mango Sandstorm, MOIS-affiliated): Deployed RustyWater — a new Rust-based RAT in early 2026 — targeting diplomatic, maritime, financial, and telecom entities. Features position-independent XOR encryption, 25+ AV/EDR evasion checks, process injection via explorer.exe hollowing, and HTTP-based C2 with triple-layer encoding (JSON > Base64 > XOR). Also deploying Dindoor backdoor leveraging Deno JavaScript runtime.
- Charming Kitten/APT35 (IRGC-IO): Intelligence collection feeding IRGC targeting operations, providing reconnaissance data for kinetic and cyber operations.
Tier 2 — State-Aligned Groups:
- CyberAv3ngers/BAUXITE (IRGC-CEC): The most operationally active ICS-targeting group. Developed IOCONTROL — a custom Linux-based IoT/OT malware using MQTT for C2, DNS-over-HTTPS via Cloudflare for resolution, and AES-256-CBC encryption. CISA confirmed 75+ US ICS devices compromised (34+ in water/wastewater sector). Actively abused ChatGPT for ICS reconnaissance including Shodan queries, default credential enumeration, Modbus TCP/IP client creation, and bash script obfuscation.
- Handala Hack Team (MOIS-aligned via Void Manticore): Deploys custom wiper malware (Hatef for Windows, Hamsa for Linux) with multi-stage delivery chains including NSIS installers, AutoIT scripts, and BYOVD exploitation. Claimed attacks against Israeli energy companies and Jordanian gas stations post-escalation.
- Additional groups: FAD Team (SCADA/PLC wiper attacks), Dark Storm Team/MRHELL112 (DDoS/ransomware), Cyber Islamic Resistance (DDoS/wiper coordination), Evil Markhors (credential harvesting), 313 Team (DDoS), DieNet (DDoS).
MALWARE ARSENAL
IOCONTROL: Custom Iranian IoT/OT cyberweapon targeting Unitronics, D-Link, Hikvision, Red Lion, Orpak, Phoenix Contact, Teltonika, and Gasboy devices. Uses MQTT protocol (ports 1883/8883) for C2 communication, DNS-over-HTTPS via Cloudflare (1.1.1.1) for domain resolution, AES-256-CBC encryption, and modified UPX packing. Persists via RC scripts (/etc/rc3.d/S93InitSystemd.sh). Supports arbitrary command execution, port scanning, self-deletion, and device information exfiltration.
TRITON/TRISIS: Industrial Safety Instrumented System (SIS) targeting malware first deployed in 2017 against a Saudi petrochemical facility. Represents the most dangerous ICS-specific capability in the Iranian arsenal — designed to cause physical destruction by disabling safety systems.
Shamoon: Destructive disk wiper that destroyed 30,000 Saudi Aramco endpoints in 2012. Remains a template for Iranian dest
Weaknesses (CWE)
CWE-798, CWE-287, CWE-306, CWE-1188
Target sectors: water-wastewater, energy, oil-gas, manufacturing, telecommunications, government, healthcare, financial, defense, aviation, maritime
Target regions: North America, Middle East, Europe, Gulf Cooperation Council
Related threats
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)
- Boggy Serpens (MuddyWater) AI-Enhanced Cyberespionage Campaign Deploying Nuso, LampoRAT, BlackBeard, Phoenix, and UDPGangster Malware
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ICS_SCADA, CRITICAL, threat intelligence, cybersecurity, T1592, T1589, T1595, T1583, T1588, T1190, T1566, T1078, T1059, T1059