Skip to main content
Blog

Shadow Fronts: The Pro-Iran Hacktivist Ecosystem Driving Disruption, Doxxing, and OT Targeting in 2026

  • July 20, 2026
  • 0 replies
  • 8 views
Dheeraj Kumar
Forum|alt.badge.img

Executive summary: 

Pro-Iran hacktivist activity in 2026 is best understood as a decentralized Iran-aligned mobilization network. It combines state-linked personas, semi-deniable proxy brands, regional ideological teams, and foreign hacktivist participants. Most activity centers on DDoS, defacement, doxxing, hack-and-leak operations, and public intimidation. A smaller but more serious subset involves destructive tooling, OT (Operational Technology) and ICS (Industrial Control Systems) targeting, identity abuse, and cyber-enabled threats. The overall activity is noisy and uneven, but the risk is real: these actors mobilize quickly, amplify claims widely, and keep their narratives closely tied to Iranian geopolitical interests. 

Handala is the most consequential public-facing brand in this activity set. Securonix ThreatWatch team assesses Handala as the highest-priority brand in the 2026 Iran-aligned hacktivist ecosystem because of its links to the MOIS-associated cluster tracked as Void Manticore, Red Sandstorm, or Banished Kitten. In 2026, Handala appeared in destructive operations, doxxing, and psychological operations, including activity tied to the March Stryker incident and the later U.S. government seizure of four MOIS-linked domains. 

Iranian-affiliated OT activity also raised the defensive priority for critical infrastructure. On April 7, 2026, FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warned that Iranian-affiliated actors had targeted internet-exposed PLCs across U.S. government facilities, water and wastewater systems, and energy organizations. The advisory described operational disruption and financial loss. Securonix ThreatWatch team also assesses Iran-nexus targeting of IP cameras across Israel and several Gulf states as relevant to both cyber defense and physical-security monitoring, especially during kinetic escalation windows.

Key takeaways: 

  • The overall threat level is high, the highest near-term risk is to Israeli organizations, U.S. and Gulf critical infrastructure, and entities with exposed OT, exposed IoT, or high public visibility. 

  • Most pro-Iran hacktivist activity in 2026 remains disruptive and narrative driven. DDoS, defacement, doxxing, inflated breach claims, and public pressure campaigns make up most of the volume. 

  • Handala should be treated as a state-linked operational persona with destructive capability, not as ordinary grassroots hacktivism. 

  • The OT and ICS risk is real. U.S. agencies disclosed PLC disruptions, and Surveillance-camera targeting is a relevant warning signal for OT-adjacent environments. 

  • Telegram remains central to the activity set. Actors use it for mobilization, propaganda, victim signaling, recruiting, and command and control in at least one FBI-documented malware campaign. 

  • Cybercrime overlap is increasing. MOIS-linked activity, criminal tooling, and hacktivist interest in ransomware ecosystems are beginning to converge. 

  • Actor claims vary sharply in credibility. Handala and CyberAv3ngers-linked activity require higher defensive priority than lower-credibility DDoS coalitions whose impact is often symbolic or overstated. 

  • Defenders should prioritize identity controls, remote-access hardening, OT exposure reduction, DDoS resilience, and destructive-recovery readiness. Actor branding should support context, not drive prioritization by itself. 


Risk Summary:

Category 

Assessment 

Primary risk 

High-volume disruption that may escalate into destructive wiping, doxxing, or OT/ICS interference. 

Most affected regions 

Israel, the United States, Gulf states, selected NATO-aligned and European countries with political, military, or supply-chain relevance. 

Most affected sectors 

Government, defense, energy, water, transportation, telecom, financial services, media, education, and healthcare. 

Common initial access or attack methods 

DDoS, defacement, compromised credentials, VPN abuse, phishing or social engineering, leak-site intimidation, PLC exploitation, camera scanning or exploitation, and misuse of legitimate administration tools. 

Likely impact 

Service outages, reputational damage, public fear, exposure of personal or operational data, endpoint disruption, and selected OT process interference. 

Defensive priority 

Reduce internet exposure, harden identity and endpoint management platforms, monitor anomalous remote access, validate OT segmentation, and rehearse destructive incident recovery. 


Geopolitical and threat context:

The threat environment accelerated after the February 28, 2026 U.S.-Israeli strikes on Iran. The escalation quickly produced a mix of retaliatory messaging, cyber operations, influence activity, and hacktivist mobilization. A sharp increase in pro-Iran hacktivist operations followed, with more than 150 incidents targeting government, finance, aviation, telecom, and critical infrastructure between February 28 and March 1. 

The activity was not confined to Iranian and Israeli systems. NCSC UK assessed that the direct threat to the United Kingdom had not changed dramatically, but organizations with regional operations or supply chains were almost certain to face higher indirect risk. That distinction matters for defenders. Pro-Iran activity in 2026 repeatedly used spillover targeting, symbolic retaliation, and target broadening against states framed as allies, facilitators, or useful amplifiers. 

Political signaling often mattered as much as technical effect. Actors paired outage claims, leak posts, and intrusion narratives with references to the "Axis of Resistance," Palestine, retaliation for strikes on Iran, or punishment of Gulf states framed as collaborators. Even when the technical impact was limited, the activity still created psychological pressure, media attention, and operational distraction. 

The year also saw a closer overlap between cyber operations and physical intimidation. Handala activity extends beyond network intrusions and includes intimidation campaigns, recruitment efforts, and physical threat signaling. DOJ actions also identified death threat emails linked to Handala infrastructure.


Actor set and activity layers:

The 2026 pro-Iran actor set is not a single group. It functions as a loose, layered structure with different levels of capability, intent, and operational control. 

The highest-risk layer includes state-linked personas and clusters. Handala and Void Manticore sit on the MOIS side. CyberAv3ngers and related OT activity sit closer to the IRGC-linked side of the activity set. These actors are the most likely to create material damage or cause defenders to misjudge severity because the activity is framed as hacktivism. 

A second layer includes ideologically aligned coalition groups. Cyber Islamic Resistance and the "Electronic Operations Room of Islamic Resistance Axis" function as umbrella-style constructs connecting teams such as 313 Team, RipperSec, Cyb3rDrag0nzz, DieNet, and related actors. There is no evidence that every member operates under direct state control, but the coordination across this layer is evident through shared narratives, overlapping target selection, and synchronized operational claims. 

A third layer includes reactivated or adjacent personas such as APTIran, Cyber Fattah, Dark Storm Team, Sylhet Gang-SG, FAD/Fatimiyoun, and Altoufan Team. These actors vary in maturity and credibility. For defenders, their value is often early warning: messaging, declared intent, and target themes can show where the broader pressure campaign is moving.

Figure 1. Pro-Iran actor set and public relationship map


Threat actor profiles:

Handala 

Aliases and attribution: Handala is assessed as a state-linked destructive persona rather than a conventional hacktivist brand. DOJ actions and infrastructure correlation associate the brand with Iran's MOIS through the Void Manticore cluster. Associated personas include Homeland Justice and KarmaBelow. 

2026 activity: Handala’s 2026 activity included the March 11 Stryker incident, the March 1 RedWanted doxxing site, PII postings tied to Israeli personnel, retaliatory messaging after the March 19 domain seizure, and the alleged compromise of FBI Director Kash Patel’s personal Gmail account. Some of the group’s claims remain unverified or likely inflated, but its infrastructure links and destructive tradecraft make it more than a publicity brand. 

Tradecraft: Handala’s tradecraft includes compromised VPN access, brute-force attempts against exposed remote services, hands-on RDP activity, NetBird tunneling, Group Policy abuse, scheduled task execution, an AI-assisted PowerShell wiper, and VeraCrypt use for destructive impact.


CyberAv3ngers 

Aliases and attribution: CyberAv3ngers is tied in U.S. government reporting and public analysis to the IRGC Cyber-Electronic Command. Tracking names associated with this activity include Shahid Kaveh Group, Hydro Kitten, Storm-0784, APT Iran, Bauxite, UNC5691, and others, depending on the tracking schema. 

2026 activity: The April 7 advisory said Iranian-affiliated actors had disrupted internet-exposed PLCs across U.S. critical infrastructure, including government facilities, water and wastewater, and energy. The advisory did not publicly name CyberAv3ngers as the 2026 operator for each event, but it tied the activity to similar historical targeting that began in 2023 and was linked to CyberAv3ngers.

Tradecraft: Observed tradecraft includes access to internet-exposed OT devices, use of Rockwell Automation and Allen-Bradley programming software, activity over common OT ports, Dropbear SSH for remote access, changes to project-file data, and interference with HMI/SCADA displays.


Cyber Islamic Resistance and the Electronic Operations Room

Role: Cyber Islamic Resistance functions as an umbrella-style coordination layer for DDoS, defacement, publicity operations, and synchronized target announcements. Some reporting also references the broader "Electronic Operations Room of Islamic Resistance Axis." 

2026 activity: This coalition layer claimed activity against Jordanian government portals, Saudi targets, Israeli payment infrastructure, drone defense systems, and several follow-on targets. The pattern shows coordinated signaling and publicity, but the underlying claims vary in reliability, ranging from confirmed outages to unverified ICS screenshots.


313 Team

Identity: 313 Team, also styled as "Islamic Cyber Resistance in Iraq," operated in 2026 as an active pro-Iran hacktivist cell. 

2026 activity: 313 Team activity in 2026 centered on DDoS and defacement claims against government, defense, and public-sector targets, including the Kuwait Armed Forces, Kuwait Ministry of Defense, Kuwait Government, Jordan’s government portal, and a Saudi academic site. The group later claimed activity against Canonical/Ubuntu, where Canonical confirmed a sustained DDoS and the actor added extortion-style messaging. The same activity stream also included claims involving Austria, Romania, Bahrain, and a U.S. consumer platform.


Dark Storm Team

Identity: Dark Storm Team presents as a pro-Palestinian and pro-Iranian collective focused on large-scale DDoS and ransomware-style disruption. Its activity also overlaps with coordinated targeting of Israeli banks, making it relevant as a financial-sector disruption actor rather than a confirmed high-end intrusion group. 

2026 activity: Dark Storm Team remains relevant as a DDoS-focused actor against symbolic Israeli financial-sector targets. The evidence base is thinner and less technical than what is available for Handala or CyberAv3ngers, so its claims should be treated with lower confidence unless supported by victim confirmation or telemetry.


FAD Team and Fatimiyoun

Identity: FAD Team, also tracked as Fatimiyoun Cyber Team or Fatimion, appears to operate as a destructive persona focused on wiper activity and permanent data loss. 

2026 activity: FAD Team claimed unauthorized access to multiple SCADA and PLC environments, devices belonging to an Israeli security-services company, and a Turkish media outlet. At this stage, the claims should be treated with caution because technical evidence remains limited.


APTIran, Cyber Fattah, DieNet, Sylhet Gang-SG, and Altoufan Team

These actors are best treated as warning layers, not consistently high-impact operators. APTIran increased Telegram-based threat messaging and posted unverified claims tied to Israeli critical infrastructure. Cyber Fattah issued messaging consistent with reconnaissance or pre-operational signaling. DieNet appeared in DDoS claims against airports and banks in Bahrain, Saudi Arabia, Jordan, and the UAE. Sylhet Gang-SG functioned more as an amplifier and DDoS participant. Altoufan Team also reappeared, likely through Cotton Sandstorm reactivation, with a particular focus on Bahraini targets. 

Assessment: Defenders should use these brands as early warning indicators, not as proof of compromise. Their messaging can help identify target themes, coalition momentum, and regional focus, but actor claims require validation through telemetry, victim confirmation, or credible technical evidence.


Attack overview:

In 2026, pro-Iran hacktivist activity followed a consistent operating cycle: a geopolitical trigger or grievance, rapid Telegram mobilization, target naming, and public claims. The follow-through usually took the form of DDoS, defacement, doxxing, leak-site pressure, credential abuse, or intrusion activity. When stronger actors entered the cycle, the activity could shift into wiping, identity abuse, OT manipulation, or cyber-enabled intimidation. 

This model serves two purposes. Lower-capability actors use it to gain visibility even when the technical impact is limited. State-linked personas use it to preserve deniability while creating operational disruption and psychological pressure. Handala is the clearest example because it pairs destructive tradecraft with public messaging, leaked material, doxxing, and direct threats.


Activity by phase:

Phase 

Observed behavior 

Associated actors or campaigns 

Useful telemetry and detections 

Confidence 

Mobilization 

Telegram announcements, target lists, revenge narratives, coalition calls. 

Handala, Cyber Islamic Resistance, 313 Team, APTIran, Cyber Fattah. 

CTI collection, Telegram and X monitoring, leak-site watchlists. Watch for target broadening and new brand creation before technical activity. 

Medium 

Reconnaissance 

Camera scanning, PLC exposure discovery, VPN brute force, provider targeting. 

Iran-nexus camera activity, Handala, PLC-targeting actors. 

Firewall, IDS, VPN, and OT sensor logs. Detect scanning against camera or PLC ports and repeated failed remote-auth attempts. 

High 

Initial access 

Valid accounts, external remote services, social engineering, messaging-app lures. 

Handala, MOIS malware, phishing clusters. 

VPN, SSO, Entra or IdP, email, endpoint, and chat-platform logs. Correlate login anomalies, new device registrations, and suspicious file transfers. 

High 

Internal movement 

RDP, WMIC, tunneling tools, remote admin abuse. 

Handala. 

EDR, Sysmon, PowerShell, process, RDP, and GPO logs. Alert on RDP from default Windows hostnames, NetBird or VeraCrypt on servers, and WMI remote process creation. 

High 

Disruption 

DDoS, defacement, endpoint wiping, MDM abuse, OT parameter manipulation. 

313 Team, Cyber Islamic Resistance, Handala, Iranian-affiliated PLC actors. 

WAF, reverse proxy, server, MDM, and OT process logs. Identify abrupt service degradation, mass endpoint actions, or HMI data changes. 

High 

Leak and intimidation 

Leak-site postings, doxxing, RedWanted, death threats, recruitment bots. 

Handala, VIPEmployment, HPRF. 

Web monitoring, email gateways, dark-web and Telegram CTI. Track disclosure sites, contact emails, Telegram bots, and victim-specific intimidation. 

High 

Amplification 

Social media recycling, mirrored claims, coalition propaganda. 

Broad actor set. 

CTI, media monitoring, and brand monitoring. Separate claim velocity from verified victim impact. 

High 

Figure 2. Common intrusion and publicity flow observed in 2026


Targeting analysis:

The 2026 target set shows a clear priority structure, with Israel at the center and spillover activity extending to the United States, Gulf states, and selected European or NATO-aligned countries. 

Israel remained the primary focus. Pro-Iran actors targeted or claimed activity against Israeli government, defense, intelligence, security, banking, oil and gas, education, and civilian-facing platforms. Israel also accounted for the largest share of conflict-linked activity tracked during the year, which reinforces its role as the main target environment for pro-Iran cyber mobilization. 

The United States moved higher in the target set as military tension with Iran increased. The Stryker incident, the Patel breach narrative, DOJ's March 19 seizure action, and the April 7 PLC advisory all point to greater willingness by Iranian-linked or Iran-aligned actors to combine symbolic retaliation with activity that can affect U.S. organizations or U.S.-based infrastructure. 

Gulf states formed a broad high-risk band. Jordan, Kuwait, Bahrain, Saudi Arabia, the UAE, and Qatar all appeared in the 2026 target set. These countries host U.S. military assets, oil and gas infrastructure, transport nodes, telecom assets, and governments that Tehran or aligned actors can frame as collaborators. Camera-targeting activity against several of these same countries adds another layer of exposure, especially for organizations with internet-facing physical security systems. 

Europe and NATO-aligned countries appeared more often in selective DDoS activity, symbolic retaliation, and supply-chain exposure than in persistent high-end intrusion activity. Austria, Romania, Cyprus, and the United Kingdom appeared in the observed or declared target set, while UK guidance emphasized indirect cyber risk for organizations with regional ties.


Campaign and cluster analysis:

MOIS brand operations centered on Handala

The strongest 2026 cluster centers on the MOIS-linked Handala brand. Handala activity spans intrusion, leak-site propaganda, doxxing, threat emails, and physical-threat extension. The evidence set includes repeated brand reuse, seized-domain overlaps, linked personas, and a consistent playbook that pairs destructive activity with psychological pressure. 

OT and infrastructure targeting

A second cluster involves Iranian-affiliated targeting of OT and infrastructure, including PLC disruption and large-scale camera reconnaissance. Not every case maps cleanly to a single persona, but the pattern is consistent: identify internet-facing industrial or surveillance systems, then use that access for disruption, visibility, intimidation, or battlefield awareness. 

DDoS coalitions under the resistance-axis narrative

The third cluster is the coalition DDoS and defacement layer involving Cyber Islamic Resistance, 313 Team, DieNet, RipperSec, and related actors. These groups often rely on uptime-checking links, recycled proof, and synchronized messaging. Their direct technical impact is usually lower than Handala-style destructive activity, but they still create public-sector disruption, media attention, customer concern, and extra workload for security and MSSP teams.


Malware, tooling, and tradecraft:

Handala destructive toolkit

Handala’s 2026 destructive stack included the custom Handala Wiper, a PowerShell wiping component, NetBird, VeraCrypt, RDP, WMIC, and GPO-based delivery. The tradecraft is notable because the actor did not rely on custom malware alone. Much of the chain used legitimate tools, remote access, and administrator-style activity, which makes malware-only detection insufficient.

Telegram-based MOIS malware

The FBI’s March 20 FLASH described a separate MOIS malware campaign using Telegram bots for command and control. Stage-one binaries masqueraded as named Windows applications. Related payloads supported screen capture, audio capture, password-protected compression, file deletion, and staged exfiltration. The campaign primarily targeted dissidents, journalists, and opposition figures, but the tradecraft has broader defensive relevance because it combines social engineering with abuse of a legitimate platform.

OT tradecraft

The April 7 advisory showed Iranian-affiliated actors using direct access methods against internet-exposed industrial controllers. The activity included operational access, project-file interaction, HMI and SCADA changes, common OT ports, and Dropbear SSH for remote control. The concern is not novel tooling. It is the willingness to act quickly against under-defended industrial endpoints during geopolitical escalation.

DDoS and booter ecosystem overlap

The 2026 DDoS pattern points to commodity booter or stresser infrastructure, uptime-checking services, and crowd-amplified declarations. The Canonical/Ubuntu campaign included commercial stresser tooling, and similar behavior appeared across coalition DDoS operations during the year.


Infrastructure analysis:

MOIS-linked domain and brand infrastructure

DOJ's March 19 seizure strengthened attribution to MOIS-linked influence and harassment infrastructure. Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to were connected through shared leak-site activity, Iranian IP ranges, and a common operational playbook. This is one of the stronger 2026 examples of hacktivist branding used to obscure state-linked activity. 

Handala operational infrastructure and OPSEC patterns

Handala infrastructure included VPS assets associated with VPN exit nodes, Starlink ranges, and repeated default Windows hostnames. The activity also included hundreds of brute-force attempts against VPN infrastructure. Several OPSEC mistakes stand out, including activity from Iranian IP space and Starlink-originating access after Iranian internet shutdowns. For defenders, the mix of commodity infrastructure and sloppy endpoint naming creates useful detection opportunities. 

Camera-targeting infrastructure

Iran-nexus camera-targeting activity used commercial VPN exits, including Mullvad, ProtonVPN, Surfshark, and NordVPN, alongside VPS infrastructure. The same infrastructure set appears across multiple Iran-nexus actors. Targeting centered on Hikvision and Dahua devices and known vulnerabilities. Scanning or exploitation of surveillance systems during escalation windows should be treated as possible warning activity, especially when it overlaps with regional conflict or kinetic events. 

Telegram as both influence fabric and operational platform

Telegram plays at least three roles in this activity set: mobilization channel for hacktivist coalitions, victim-signaling and recruiting channel for Handala-linked offshoots, and command-and-control channel in the MOIS malware campaign documented by the FBI. That makes Telegram-related telemetry relevant across CTI, SOC, executive protection, and insider-risk workflows.

Figure 3. Infrastructure and platform relationships


Securonix ThreatWatch summary:

Securonix ThreatWatch team recommended focusing defensive coverage on exposed remote access, identity and privilege abuse, internet-facing OT and ICS assets, DDoS resilience, and leak or intimidation infrastructure. These areas are the most likely pressure points for pro-Iran hacktivist activity in 2026.

Priority 

Action 

What to do 

Evidence to check 

Relevant telemetry 

Critical 

Audit remote access and privilege 

Review VPN/SSO exposure, MFA coverage, high-risk roles, and anomalous login history. 

Failed-success login chains, new admin assignments, default Windows hostnames. 

VPN, IdP, Entra, EDR. 

Critical 

Harden MDM / Intune 

Restrict wipe permissions, require secondary approval, and review service principals and admin roles. 

Mass wipe or reset actions, anomalous role use, unexpected geographies. 

Intune / MDM audit logs. 

Critical 

Reduce OT exposure 

Remove direct internet exposure from PLCs, HMIs, and field modems. 

OT ports, internet reachability, project-file changes. 

OT firewall, asset inventory, engineering logs. 

High 

Hunt destructive tool patterns 

Search for NetBird, VeraCrypt, PowerShell wipe behavior, scheduled tasks, and GPO edits. 

Tool hashes, process chains, script content. 

Sysmon, PowerShell, Windows logs, EDR. 

High 

Monitor public threat infrastructure 

Track Handala domains, Telegram channels, RedWanted-style sites, and VIPEmployment bots. 

Mentions of brand, organization, executives, staff, or victims. 

CTI platform, external monitoring, web logs. 

Medium 

Improve DDoS resilience 

Validate provider capacity, failover, rate controls, and external communications. 

CDN/WAF anomalies, service degradation, uptime-check claims. 

WAF, load balancers, application logs. 

Medium 

Strengthen diaspora and executive protection workflows 

Coordinate CTI with legal, HR, and protective-security stakeholders for doxxing or death-threat cases. 

Threat emails, leaked PII, targeted social posts. 

Email gateway, CTI, protective intelligence. 


Detection artifacts and hunt ideas:

The stronger analytic pivot is behavior, not actor naming. The higher-risk activity clusters around repeatable signals: anomalous remote access, VPN abuse, privileged actions in endpoint management or MDM platforms, and destructive use of RDP, WMIC, GPO, scheduled tasks, and PowerShell. Defenders should also watch for suspicious use of NetBird, VeraCrypt, Dropbear, and similar tunneling or administrative tools, along with inbound access to OT ports or exposed camera interfaces from suspicious infrastructure.


Relevant telemetry sources:

Telemetry source 

Why it matters 

VPN, SSO, and IdP logs 

Detects compromised VPN access, brute-force attempts, abnormal login patterns, and suspicious identity use. 

Microsoft Entra, Intune, and MDM audit logs 

Captures high-risk endpoint management actions, device policy changes, enrollment abuse, and remote administrative activity. 

Windows Security, Sysmon, and EDR 

Required to detect RDP, WMI, scheduled tasks, PowerShell, GPO changes, file hashes, and tool execution. 

Web, DNS, and proxy logs 

Helps identify access to Handala-linked domains, RedWanted infrastructure, Telegram abuse, NetBird or VeraCrypt downloads, and leak-site activity. 

OT and ICS firewall and sensor logs 

Required for PLC port monitoring, access to exposed industrial devices, and suspicious interaction with control-system assets. 

WAF, reverse proxy, and CDN telemetry 

Separates symbolic DDoS claims from availability-impacting events and helps measure real service disruption. 

Threat intelligence and external monitoring 

Tracks Telegram channels, doxxing sites, recruitment bots, leak infrastructure, and actor signaling tied to emerging targeting 


Defender implications:

Pro-Iran hacktivist activity should not be dismissed as background noise. Much of it is loud and inflated, but the activity set also includes state-linked personas with destructive capability, operators focused on OT exposure, and brands willing to pair cyber activity with intimidation. 

Speed is the defender’s problem. Coalition actors can move from declaration to impact quickly because they often reuse infrastructure, mobilize through Telegram, and rely on commodity disruption tools. CTI, executive protection, SOC operations, and crisis communications need to work from the same picture. A leak-site post, Telegram bot, DDoS burst, and anomalous privileged login may be separate events, or they may be parts of the same campaign. 

The practical enablers are familiar: exposed internet services, weak remote-access hygiene, identity abuse, loose endpoint management, and internet-facing OT. The defensive priority is not exotic tooling. It is closing the access points these actors already use.


Defensive control points:

Lifecycle stage 

Control point 

Defender action 

Mobilization 

Telegram and leak-site monitoring 

Watch new actor declarations, target lists, and recruitment posts. 

Reconnaissance 

Exposure management 

Identify internet-exposed PLCs, cameras, VPN gateways, and remote desktop surfaces. 

Initial access 

MFA and conditional access 

Enforce phishing-resistant MFA, block risky sign-ins, and tighten remote-service exposure. 

Lateral movement 

Server and admin telemetry 

Detect RDP, WMI, tunneling tools, and unusual admin utility downloads. 

Destruction 

Change control and backup integrity 

Lock GPOs, validate backups, and monitor mass task creation and endpoint actions. 

Public intimidation 

CTI, legal, and executive protection 

Respond quickly to doxxing, death threats, and public disclosure campaigns. 

Recovery 

Business continuity 

Rehearse DDoS, wiper, MDM abuse, and OT restoration scenarios. 


Defensive recommendations:

For executives: Treat this threat as a resilience issue, not a social-media problem. Review remote-access exposure, MDM governance, and internet-facing OT. Crisis communications and legal teams should also be ready for doxxing, leak-site pressure, and threat-mail scenarios. 

For SOC teams: Correlate identity, endpoint, OT, and web-edge telemetry. Prioritize detections for authentication anomalies, destructive administrator activity, and endpoint-management misuse. Actor names can support enrichment, but behavior should drive detection logic. 

For CTI teams: Monitor Telegram and leak infrastructure for pre-attack signaling, target expansion, recruitment, and intimidation posts. Use clear confidence labels. Screenshots and actor-generated proof should not be treated as validation on their own. 

For MSSPs: Expect symbolic targeting and customer concern to move faster than confirmed impact. Prepare communication templates for DDoS, doxxing, and public-claim scenarios. Keep enrichments current for VPN ASN categories, Telegram-linked indicators, and OT exposure alerts. 

For critical infrastructure operators: Review PLC exposure, remote engineering paths, field modem security, backup procedures, and project-file change monitoring. Do not assume perimeter controls are enough when controllers or support systems are directly reachable from the internet. 

For ICS and OT defenders: Validate device mode settings, route remote access through secure gateways, monitor HMI and SCADA changes, and bring engineering workstations under identity, EDR, and privileged-access controls. Treat reconnaissance against surveillance systems as possible warning activity, especially during regional escalation.


MITRE ATT&CK mapping:

Tactic 

ATT&CK technique 

Initial Access 

T1133 External Remote Services; T1078 Valid Accounts; T1566 Phishing or social engineering 

Credential Access 

T1110 Brute Force; T1003.001 LSASS dumping; T1003.002 SAM-related credential extraction 

Discovery 

T1087.002 Account Discovery 

Lateral Movement 

T1021.001 RDP 

Execution 

T1047 WMI; T1059.001 PowerShell; T1053.005 Scheduled Task; T1105 Ingress Tool Transfer 

Command and Control 

T1572 Protocol Tunneling; legitimate service abuse involving Telegram 

Persistence 

T1484.001 Group Policy Modification; T1037.003 Network Logon Script 

Impact 

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1498 Network DoS; T1491.001 Defacement; T1561.002 Disk Structure Wipe; T1565 Stored Data Manipulation 

ATT&CK for ICS 

T0883 Internet Accessible Device; T0885 Commonly Used Port 


Analyst comment:

Treat this as a mixed activity set, not a single cyber force. It includes loud DDoS crews, coalition brands, proxy personas, and state-linked operators. Some actors mainly generate visibility. Others use hacktivist branding while carrying out disruption, data theft, or intimidation. That mix lets Tehran-aligned interests combine propaganda, deniability, and opportunistic disruption without requiring every participant to have advanced capability. 

Handala is the warning case. It shows how an actor can use activist branding while supporting destructive operations, leak-site pressure, and physical-threat messaging. The hacktivist label should not lower severity by default. In 2026, some of the most serious Iran-linked incidents surfaced through brands built for hacktivist-facing audiences.


Outlook:

This report does not forecast specific incidents. Based on the 2026 activity pattern, pro-Iran actors are likely to keep using Telegram mobilization, symbolic DDoS, doxxing, and leak-site intimidation while confrontation involving Iran remains elevated. 

State-linked personas are also likely to keep exploiting the ambiguity created by lower-tier hacktivist campaigns. Critical infrastructure entities with exposed OT or IoT assets, and enterprises with weak identity governance or overpowered endpoint management controls, should remain on alert. Cyber-enabled physical intimidation under established hacktivist brands is plausible and should be handled as both a cyber and protective-security issue.


References:

[1] Check Point Research, Handala Hack: Unveiling Group's Modus Operandi. https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/ 

[2] IC3 / FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command, Cybersecurity Advisory 260407. https://www.ic3.gov/CSA/2026/260407.pdf 

[3] SOCRadar, Iran-Israel Cyber Conflict Dashboard. https://socradar.io/iran-israel-cyber-conflict-dashboard/ 

[4] FBI, Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. https://www.fbi.gov/file-repository/government-of-iran-cyberactors-deploy-telegram-c2-to-push-malware-to-identified-targets.pdf 

[5] Check Point Research, Iranian MOIS Actors: The Cyber Crime Connection. https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/ 

[6] U.S. Department of Justice, Justice Department Disrupts Iranian Cyber-Enabled Psychological Operations. https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations 

[7] Unit 42, Handala Hack Wiper Attacks. https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/ 

[8] U.S. Securities and Exchange Commission, Stryker Form 8-K filing. https://www.sec.gov/Archives/edgar/data/310764/000119312526102460/d76279d8k.htm 

[9] Wired, Handala Hacker Group Iran US Israel War. https://www.wired.com/story/handala-hacker-group-iran-us-israel-war 

[10] CloudSEK, Middle East Escalation: Israel, Iran, U.S. Cyber War 2026. https://www.cloudsek.com/blog/middle-east-escalation-israel-iran-us-cyber-war-2026 

[11] NCSC UK, NCSC Advises UK Organizations to Take Action Following Conflict in Middle East. https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east 

[12] Recorded Future, Iran, Handala, and Physical Threats. https://www.recordedfuture.com/research/iran-handala-physical-threats 

[13] Unit 42, Iranian Cyberattacks 2026. https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ 

[14] The Register, Pro-Iran Group Turns Ubuntu DDoS Into Shakedown. https://www.theregister.com/security/2026/05/01/pro-iran-group-turns-ubuntu-ddos-into-shakedown/5224575 

[15] Sophos, Hacktivist Campaigns Increase as United States, Iran, and Israel Conflict Intensifies. https://www.sophos.com/en-us/blog/hacktivist-campaigns-increase-as-united-states-iran-and-israel-conflict-intensifies 

[16] Check Point Research, Interplay Between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East. https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/ 

[17] U.S. Attorney's Office, District of Maryland, Justice Department Disrupts Iranian Cyber-Enabled Psychological Operations. https://www.justice.gov/usao-md/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations 

[18] Ubuntu Discourse, Update Concerning DDoS Attack on Canonical and Ubuntu. https://discourse.ubuntu.com/t/update-concerning-ddos-attack-on-canonical-and-ubuntu/81482 

[19] The Record, FBI, CISA Warn of Microsoft Intune Risks After Stryker. https://therecord.media/fbi-cisa-warn-of-microsoft-intune-risks-stryker