Iran-Linked Hackers Build Persistent Access for Potential Wartime Disruption
Iran-linked hackers are quietly compromising corporate accounts, cloud environments, IT providers, and industrial systems that could support future disruption. Much of the activity currently centers on espionage and persistent access rather than immediate destructive attacks.
A SentinelLabs assessment describes this strategy as “access optionality.” An account or remote-management foothold acquired for intelligence collection can later support data theft, lateral movement, coercion, or selective disruption.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The threat does not come from a single coordinated hacking group. Iran’s cyber ecosystem includes operators linked to intelligence agencies, military organizations, state-aligned personas, surveillance teams, and opportunistic attackers with different objectives and capabilities.
What access optionality means for targeted organizations
Cyber access can remain useful long after the initial intrusion. Attackers may quietly monitor email, collect credentials, map trusted relationships, or identify systems that could become valuable during a political or military crisis.
A compromised supplier or service provider can expose customer identities and administrative connections. However, access to a supplier does not automatically prove a software supply-chain attack unless the operator compromises customers, software builds, updates, or distribution systems.
The strategic concern involves the options available to the attacker. Previously acquired access may support several missions without requiring a new intrusion when geopolitical conditions change.
| Access path | Immediate use | Possible later use |
|---|---|---|
| Compromised cloud account | Email and document collection | Impersonation, phishing, and internal targeting |
| Remote management tool | Monitoring or administrative access | Organization-wide disruption or malware deployment |
| IT service provider | Intelligence about customers | Access to downstream client environments |
| Industrial controller | Reconnaissance and configuration theft | Process interference or operational outages |
| Privileged user account | Collection of sensitive conversations | Identity abuse and lateral movement |
Seedworm and other groups pursue long-term access
Activity attributed to the MOIS-linked Seedworm cluster, also known as MuddyWater, reportedly affected a US bank, a US airport, nonprofit organizations, and the Israeli operation of a US software supplier.
Researchers found multiple backdoors and an attempted transfer of information to commercial cloud storage. The intrusions began before the current escalation, so the evidence does not establish that every compromise started as deliberate wartime preparation.
However, a foothold inside a financial institution, airport, supplier, or trusted administrator can gain new strategic value during a conflict. Operators can continue intelligence collection or redirect the access toward more disruptive objectives.
Recruitment phishing targets people with trusted access
Screening Serpens, also tracked under names including UNC1549 and Smoke Sandstorm, has used tailored recruitment campaigns to deliver remote-access malware. Apparent targets included organizations or individuals in the United States, Israel, the United Arab Emirates, and the wider Middle East.
These campaigns reportedly deployed six new remote-access Trojan variants between February and April 2026. The attackers combined convincing employment lures with techniques designed to execute malicious code and maintain access.
Recruitment phishing can prove particularly effective against people with valuable professional relationships. One compromised account may expose internal discussions, cloud documents, contact lists, and information attackers can use to impersonate trusted colleagues.
- Executives and senior administrators
- Journalists, researchers, and academics
- Government-linked employees
- Defense and aerospace personnel
- IT support staff and managed service providers
- Employees with access to cloud administration tools
Service providers can create access to multiple customers
Attackers do not always need to exploit a new software vulnerability. They can misuse access already granted to an administrator, identity provider, remote monitoring platform, support company, or service account.
Recent reporting on the cluster tracked as Cavern Manticore described intrusions involving existing remote monitoring and management access inside compromised IT-provider environments. Researchers assessed a relationship with Iran’s Ministry of Intelligence and Security at moderate confidence.
Such incidents require careful wording. Abuse of a legitimate deployment feature does not necessarily mean attackers compromised the software vendor or exploited a vulnerability in its product.
Public personas combine hacking with psychological pressure
Iran-linked personas such as Handala Hack Team, Homeland Justice, and KarmaBelow80 publicly claim attacks, publish stolen information, threaten individuals, and amplify the perceived impact of intrusions.
In March 2026, the US Justice Department seized four domains that it linked to Iranian Ministry of Intelligence and Security operations. Investigators said the domains shared infrastructure, Iranian IP ranges, and an operational playbook combining cyberattacks with data leaks and threats.
These personas function as more than publicity channels. They can conceal attribution, pressure victims, intimidate critics, and establish a public narrative before investigators determine what happened inside the affected network.
| Actor or persona | Primary activity described by researchers |
|---|---|
| Seedworm or MuddyWater | Espionage, backdoor deployment, and persistent access |
| Screening Serpens | Recruitment-themed social engineering and remote-access malware |
| APT42 | High-trust social engineering and cloud account collection |
| Cavern Manticore | Service-provider and remote-management access |
| Handala, Homeland Justice, and Karma | Destructive claims, leaks, coercion, and influence operations |
| CyberAv3ngers | Opportunistic targeting of operational technology |
Stryker attack shows the gap between claims and confirmed facts
Handala claimed responsibility for the March 2026 cyberattack on medical technology company Stryker. The Justice Department said an MOIS-controlled Handala domain claimed the destructive attack against a US medical technology company.
Stryker confirmed that the incident disrupted its global Microsoft environment, including systems supporting ordering, manufacturing, and shipping. The company later found that the attacker used a malicious file to run commands and conceal activity.
That file could not spread within or outside Stryker’s environment. In its customer security updates, the company said the incident did not compromise its products or customer, supplier, vendor, and partner systems.
Stryker did not publicly attribute the intrusion to Handala. It also did not validate the persona’s claims about the number of affected devices, the use of a wiper, or the volume of allegedly destroyed or stolen data.
Iran-affiliated hackers are targeting industrial controllers
The clearest evidence of potentially disruptive activity concerns internet-connected operational technology. An updated joint US government advisory warns that Iran-affiliated actors are targeting programmable logic controllers across several critical infrastructure sectors.
The activity initially highlighted Rockwell Automation and Allen-Bradley PLCs. The July update expanded the warning to include targeting involving Schneider Electric and Siemens equipment, along with potentially other manufacturers.
Government agencies documented malicious interaction with PLC project files and manipulation of information shown on human-machine interface and SCADA displays. Some affected organizations experienced operational disruption and financial losses.
The targeted sectors include:
- Government services and municipal facilities
- Water and wastewater systems
- Energy organizations
- Other operators using exposed industrial controllers
Access to an industrial interface does not prove physical control
Pro-Iran channels have published images and videos that appear to show industrial dashboards, engineering applications, and SCADA interfaces. Such material can indicate exposure, but a screenshot alone does not prove control over a physical process.
Investigators need to determine whether the actor merely found a login page, entered a live system, changed a configuration, or produced a measurable operational effect. Each conclusion requires stronger technical evidence.
Analysts can assess industrial compromise claims through the following evidence levels:
- Confirm the target organization, system, location, and timeframe.
- Establish whether the actor could only view a login page or interface.
- Verify authenticated access to current system information.
- Determine whether the actor could change logic, settings, or operating modes.
- Confirm that a change affected an operational process.
- Document any physical, safety, financial, or service consequence.
Logs, project files, process data, engineering analysis, operator testimony, and independent confirmation provide stronger evidence than social media claims. Attackers may exaggerate their access to increase psychological and reputational pressure.
Internet exposure makes industrial disruption easier
Many operational technology attacks succeed because organizations expose controllers, engineering services, or management interfaces directly to the internet. Default credentials and poorly controlled vendor access can turn a technically simple intrusion into a serious operational incident.
The risk increases when business and industrial networks lack effective segmentation. An attacker who compromises an IT administrator or service provider may then gain a path toward engineering workstations and operational controls.

The updated CISA advisory recommends removing direct internet exposure, changing default credentials, validating controller project files, and investigating unexpected changes to industrial logic and configurations.
Defenders should review trusted access before a crisis
Organizations should identify every account, vendor, service provider, and remote-management product capable of changing critical systems. Security teams should then determine whether each access path remains necessary and properly restricted.
Remote access should require phishing-resistant MFA and an authenticated gateway. Organizations should restrict vendor connections by user, source, role, system, and approved time window.
Recovery infrastructure also needs separate protection. Backups and fallback systems may fail during the same incident if they share production credentials, identity services, virtualization platforms, administrators, or upstream providers.
| Area | Recommended action |
|---|---|
| Identity | Enforce phishing-resistant MFA and investigate unfamiliar cloud sessions |
| Remote management | Limit access by source, user, role, device, and time |
| Service providers | Review delegated permissions and monitor administrative activity |
| Operational technology | Remove direct internet exposure and segment industrial networks |
| Engineering systems | Monitor logic changes, project files, workstations, and industrial protocols |
| Recovery | Maintain offline configurations and test isolated restoration procedures |
| Incident response | Coordinate technical, legal, communications, and employee-safety teams |
Large-scale grid disruption is not the expected near-term outcome
The public evidence supports continued espionage, credential theft, cloud compromise, and development of persistent access. Iran-linked operators may attempt selective disruption when they already have usable access and the target offers political or symbolic value.
SentinelLabs assessed with moderate confidence that a coordinated campaign to disable the US power grid or several critical sectors simultaneously remains a lower-likelihood but high-impact scenario. Researchers found no public evidence of the synchronized access and specialized preparation required for an imminent nationwide operation.
The more likely industrial incidents involve internet-exposed systems, weak passwords, known vulnerabilities, and poorly controlled remote engineering. These weaknesses can still produce significant consequences when the targeted environment lacks resilience.
Persistent access remains the central threat
The SentinelLabs outlook expects continued intelligence collection and access development, accompanied by public personas that exaggerate or amplify technical effects.
Security teams should focus on access, mission, and shared dependencies rather than the volume of public claims. A compromised identity or support tool becomes more dangerous when it connects to several systems that can fail together.
Removing exposed industrial equipment, reducing persistent administrative access, securing service-provider connections, and separating recovery systems can prevent an ordinary account compromise from becoming a tool for wartime disruption.
FAQ
Access optionality describes a foothold that can support different missions over time. Attackers may initially use it for espionage before redirecting it toward data theft, lateral movement, coercion, or disruption.
Public reporting shows repeated targeting of exposed industrial systems, but researchers found no evidence of the coordinated access and specialized preparation required for an imminent nationwide grid attack.
US agencies have documented targeting of internet-connected programmable logic controllers, including equipment from Rockwell Automation, Allen-Bradley, Schneider Electric, and Siemens.
Handala claimed responsibility, and the Justice Department linked the claim to an Iranian intelligence-controlled domain. However, Stryker did not publicly attribute the attack to Handala or confirm the group’s claims about its impact.
Organizations should secure cloud identities, restrict remote administration, review service-provider access, remove industrial systems from the public internet, segment operational networks, and maintain isolated recovery systems.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages