Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military Operations (2026 Conflict)
Iran's AI-Enhanced Asymmetric Playbook (TL-2026-1417), also tracked as Operation Olalampo, is a high-severity tracked threat-actor profile, first published 2026-07-16. It is attributed to APT42 (Iran) with medium confidence, affects Various Microsoft Office (macro-enabled documents), maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1417
- Threat ID
- TL-2026-1417
- Also known as
- Operation Olalampo, Operation Epic Fury, Operation Roaring Lion
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-07-16
- Last reviewed
- 2026-07-16
- Attribution
- APT42
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, aerospace, aviation, telecoms, energy, transport, maritime, criticalinfrastructure, humanrightsngo, civil society, technology
- Target regions
- North America, Middle East, Europe, Gulf States, iraq, israel, iran
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Iran's AI-Enhanced Asymmetric Playbook
Malware and tooling: CHAR, GHOSTFORM, GhostBackDoor, GhostFetch, HTTP_VIP, MiniFast, MiniJunk, SPLITDROP, SloppyMIO, TWINTALK, TWINTASK, AnyDesk
Recorded Future documents Iranian state-linked actors — IRGC-affiliated groups, MOIS, APT42/GreenBravo, MuddyWater/GreenGolf, APT34/OilRig, RedKitten, Dust Specter, Nimbus Manticore, plus hacktivist personas CyberAv3ngers, Cyber Isnaad Front, and Ababil of Minab — integrating AI (Gemini, ChatGPT) into cyber operations, influence campaigns, military systems, and domestic surveillance during the January-June 2026 conflict with the US and Israel. AI functioned as a force multiplier accelerating existing tradecraft (spearphishing, malware development, ICS reconnaissance, propaganda) rather than creating breakthrough capabilities.
How Iran's AI-Enhanced Asymmetric Playbook works
During the January-June 2026 US/Israel-Iran conflict (Operation Epic Fury/Roaring Lion, February 28 airstrikes, through the June 17 collapse of a US-Iran memorandum of understanding), Recorded Future assessed that Iranian state and IRGC-affiliated actors integrated generative AI tools across cyber operations, information warfare, military systems, and domestic surveillance. The clearest AI impact was in information warfare, where large language models and image generators (including Freepik.com) enabled rapid, culturally-nuanced propaganda production distributed across Instagram, Bluesky, TikTok, and X/Twitter, including a documented case of AI-generated Lego-themed propaganda video content.
On the cyber front, multiple Iranian APT clusters independently adopted AI-assisted malware development, evidenced by AI-generated code artifacts (excessive defensive/error-handling logic, embedded emoji/unicode patterns, and placeholder hardcoded seed values such as 0xABCDEF) discovered in malware from Dust Specter (TWINTALK/GHOSTFORM), Nimbus Manticore (MiniFast), and RedKitten-linked SloppyMIO. MuddyWater (GreenGolf) launched Operation Olalampo on January 26, 2026, targeting MENA organizations via phishing documents with malicious macros dropping the GhostFetch downloader, GhostBackDoor implant, HTTP_VIP native downloader, and the Rust-based Telegram-controlled CHAR backdoor. RedKitten (newly identified January 2026, overlapping Yellow Liderc/Imperial Kitten TTPs) targeted Iranian human-rights NGOs and protest documentarians with 'Tehran Forensic Medical Files' shock-lure archives delivering the SloppyMIO implant, which used GitHub and Google Drive for staging and Telegram for C2. Nimbus Manticore resurfaced during Operation Epic Fury (from February 28, 2026) targeting US, European, and Middle Eastern aviation and software/defense/aerospace/telecom organizations with the AI-assisted MiniFast backdoor (64-bit Windows PE DLL impersonating Chrome), delivered via phishing and, from April 2026, SEO-poisoned fake SQL Developer installer pages. Dust Specter (APT34/OilRig-linked, medium-to-high confidence Iran-nexus) targeted Iraqi government officials via compromised Iraqi government infrastructure using two attack chains: SPLITDROP dropper with TWINTASK/TWINTALK backdoors, and the consolidated in-memory GHOSTFORM RAT executing PowerShell retrieved from C2 without writing to disk.
Separately, Recorded Future documented an ICS/OT reconnaissance capability enabling analysts to move from expressed intent to a list of accessible US industrial control system devices within five minutes using AI-assisted search/enumeration, targeting energy, transportation, aviation, and maritime/shipping logistics sectors, and industrial refrigeration/PLC systems. Hacktivist proxy personas amplified the campaign: CyberAv3ngers (historically linked to IRGC Cyber Electronic Command and prior Unitronics PLC defacements) continued ICS-themed messaging; Cyber Isnaad Front (FDD-assessed likely Iranian proxy) claimed breaches of over 160 Israeli telecom data centers, exfiltration of 5TB from a national fuel logistics provider, and compromise of Israeli logistics/tracking and government/military communications systems, though independent verification found many claims overstated; Ababil of Minab (MOIS-linked) conducted parallel hacktivist activity. Iran also received external support: Russia supplied Shahed-236/MS001 drone hardware with Nvidia Jetson Orin AI modules, tactical/flight-planning tradecraft, satellite imagery, and FindFace facial-recognition technology; China supplied surveillance infrastructure (Huawei/ZTE deep packet inspection, Hikvision/Tiandy cameras) and geospatial-AI target-identification tooling (MizarVision), reinforcing a domestic surveillance apparatus originally built for hijab-law enforcement and expanded during an 88-day nationwide internet blackout (beginning January 8, 2026) to suppress protests.
Recorded Future's overall assessment: AI 'almost certainly enhanced' Iran's asymmetric playbook by accelerating existing tradecraft velocity and scale, but had 'not fundamentally altered' Iranian strategic doctrine; confirmed operational integration of AI into live military systems (beyond drone guidance hardware) remains unconfirmed.
MITRE ATT&CK techniques used in TL-2026-1417
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Initial Access
T1189 Drive-by Compromise; T1199 Trusted Relationship; T1566 Phishing
Impact
T1485 Data Destruction; T1491 Defacement
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Reconnaissance
T1593 Search Open Websites/Domains; T1596 Search Open Technical Databases
Affected products and versions in Iran's AI-Enhanced Asymmetric Playbook
- Various — Microsoft Office (macro-enabled documents)
Vulnerable versions: all versions with macros enabled
Fixed in: macros disabled by default / Protected View enforced - Various — Industrial Control Systems / PLCs (industrial refrigeration, energy, transportation, maritime)
Vulnerable versions: internet-exposed ICS/OT devices
Fixed in: network-segmented, non-internet-exposed configurations - Various — Aviation, defense, aerospace, and telecom sector enterprise networks (US, Europe, Middle East)
Vulnerable versions: endpoints without EDR behavioral detection
Fixed in: N/A - social-engineering/malware campaign, not a software vulnerability
Remediation for Iran's AI-Enhanced Asymmetric Playbook
Immediate actions
- Block delivery of password-protected 7z archives from unsolicited email in high-risk NGO/activist environments
- Disable Office macro execution by default; alert on VBA macro-spawned child processes (cmd.exe, powershell.exe, mshta.exe)
- Block outbound Telegram Bot API traffic from endpoints where not business-justified
- Monitor for AnyDesk deployment from unexpected parent processes following native downloader execution
- Restrict/monitor use of GitHub raw content and Google Drive direct-download URLs as executable staging channels on managed endpoints
- Segment ICS/OT networks from internet-reachable IT assets and restrict remote access to PLCs and industrial refrigeration controllers
- Alert on unsigned or newly-compiled 64-bit PE DLLs masquerading as Chrome components
Workarounds
- Enforce application allowlisting to prevent execution of downloader-staged secondary payloads in memory
- Require out-of-band verification for unsolicited 'casualty list' or forensic-document-themed archives before opening
Longer-term hardening
- Deploy EDR with behavioral/in-memory detection for fileless PowerShell execution retrieved from C2 (GHOSTFORM-style tradecraft)
- Establish continuous ICS/OT asset discovery and exposure monitoring to counter AI-accelerated adversary reconnaissance
- Build detection content tuned to AI-generated malware artifacts (placeholder seed values, excessive defensive coding patterns, embedded emoji/unicode in binaries)
- Expand threat-hunting coverage for MENA/Gulf critical infrastructure, aviation, and defense/aerospace/telecom sectors given active Iranian APT targeting
- Coordinate with NGO/civil-society CERTs to distribute IOCs and takedown requests for shock-lure phishing infrastructure targeting activists
Timeline of Iran's AI-Enhanced Asymmetric Playbook
- Iran begins an 88-day nationwide internet blackout, coinciding with expanded AI-assisted domestic surveillance and protest-crackdown infrastructure.
- HarfangLab obtains RedKitten campaign malicious samples targeting Iranian human-rights NGOs and protest documentarians.
- MuddyWater (GreenGolf) launches Operation Olalampo, targeting MENA organizations with phishing documents delivering GhostFetch, GhostBackDoor, HTTP_VIP, and the CHAR Rust backdoor.
- HarfangLab publishes analysis of the RedKitten campaign and its AI-accelerated tooling (SloppyMIO implant).
- US and Israeli forces conduct coordinated airstrikes on Iran (Operation Epic Fury / Roaring Lion), triggering surge in Iranian state and hacktivist cyber activity.
- Dust Specter (APT34/OilRig-linked) targets Iraqi government officials using compromised Iraqi government infrastructure, deploying SPLITDROP/TWINTASK/TWINTALK and the consolidated GHOSTFORM RAT.
- Nimbus Manticore resurfaces during Operation Epic Fury targeting aviation, defense, aerospace, and telecom organizations with the AI-assisted MiniFast backdoor.
- Iran claims a strike on the USS Abraham Lincoln; an explosive drone boat targets vessel MKD VYOM.
- Alleged Iranian Arash-2 strike on Ben Gurion Airport.
- IRGC Navy Commander Tangsiri killed in an Israeli strike.
- ChatGPT-refined attack reported against the Vyncs GPS tracking service.
- Nimbus Manticore adds SEO poisoning (fake SQL Developer installer pages) as a MiniFast delivery vector.
- Recorded Future publishes 'Iran's AI-Enhanced Asymmetric Playbook,' synthesizing the January-June 2026 campaign.
- The US-Iran memorandum of understanding collapses, marking the close of the analyzed conflict period.
Sources cited for Iran's AI-Enhanced Asymmetric Playbook
- Iran's AI-Enhanced Asymmetric Playbook
- Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists
- RedKitten: AI-accelerated campaign targeting Iranian protests
- MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
- Operation Olalampo: MuddyWater's Expanding Campaign Across MENA
- Operation Olalampo: Inside MuddyWater's Latest Campaign
- Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict
- IRGC-linked Nimbus Manticore group attacks defense, aerospace, telecom sectors using Minifast malware toolkit
- Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
- Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
- Dust Specter APT Targets Government Officials in Iraq
- FDD flags Cyber Isnaad Front as likely Iranian proxy after group posts Israeli data from alleged hacks
- Iran's Pro-Regime Hackers Cannot Back Up Their Claims of Successful Cyber Attacks
- Cyber Warfare in the US-Israel vs Iran Conflict (Roaring Lion & Epic Fury)
- Iran vs. Israel & US Cyber War 2026: Operation Epic Fury Threat Intelligence
More in threat actor
- ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains
- Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign
Detection coverage for TL-2026-1417
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1417 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.