Bombs, Drones, and Malware: The War With Iran Isn’t Just Happening in the Sky
A hidden conflict now unfolding through networks, infrastructure, and digital sabotage
DEAR READER: Please consider a basic support membership at $5 per month. As a journalist in Ukraine, I work every day (even during blackouts and drone attacks) to examine our world situation from where the fulcrum of the world’s hell pivots, and your help is vital. Today is my 1429th day in this 1475 of full-scale war (4401 since 2014), and Independent Journalism is not cheap to do, and I will keep making the posts available for all readers (even during nearly 24 hr daily blackouts), but good patrons are needed and I thank you for your time. – Chris Sampson, Kyiv, March 10, 2026
INTRO:
At 2:30 in the morning on February 28, 2026, Donald Trump posted an eight-minute video to Truth Social announcing that the United States had begun major combat operations against Iran. No prime-time address. No formal address to Congress. No Senate vote. Truth Social. At 2:30 AM.
By the time most Americans woke up, it was already history.
Operation Epic Fury — the American codename; Israel called it Operation Roaring Lion — launched nearly 900 strikes in the first twelve hours. The target list included Iranian ballistic missile infrastructure, nuclear sites, IRGC command facilities, the Iranian Navy, and Iranian leadership. By nightfall, Supreme Leader Ali Khamenei was dead, killed in a strike on his compound in central Tehran. IRGC commander Mohammad Pakpour was dead. Defense Minister Aziz Nasirzadeh was dead. The chief of staff of the Iranian Armed Forces was dead. A senior Khamenei adviser was dead. In one morning, the Islamic Republic lost most of the men who had been running it.
Iran’s response was immediate and wide. Over 500 ballistic missiles and nearly 2,000 drones fired since February 28. Forty percent targeting Israel. Sixty percent aimed at American bases and allies across the region. Kuwait International Airport struck. Dubai Airport hit. The Burj Al Arab hotel on fire from drone debris. A synagogue in Beit Shemesh, Israel, hit — nine people killed, forty-nine wounded. A girls’ primary school in Minab, southern Iran, struck during the opening wave — 165 students and staff dead, a civilian casualty that the U.S. and Israel are still disputing responsibility for.
Six American service members killed. A shooting at a bar in Austin, Texas, by a man wearing an Islamic Republic flag undershirt. Gunfire into an Iranian-Canadian activist’s gym outside Toronto within hours of Khamenei’s death. Iran’s sleeper cell infrastructure activating in real time.
The world’s cameras pointed at the missile contrails, the burning warships, the satellite imagery of Khamenei’s compound reduced to rubble. Standard operating procedure. See the thing that makes the fireball. Report on the fireball. Repeat.
But there is another war running underneath this one. It has been running for sixteen years. It doesn’t make fireballs. It doesn’t appear on satellite imagery. It runs through the same fiber optic cables that carry your banking login, your hospital’s patient records, your city’s water treatment controls, and your government’s email.
And to understand it, you have to go back to the moment the United States and Israel handed Iran the blueprint.
THE LESSON AMERICA TAUGHT
Before Iran was a sophisticated offensive cyber power, it was a target.
The U.S. and Israeli intelligence services had a problem in the mid-2000s: Iran was building centrifuges at its Natanz nuclear facility to enrich uranium, and no one wanted to bomb them. Too messy. Too escalatory. Too many second-order consequences. So they built something else instead.
The program was called Operation Olympic Games, launched during the Bush administration and dramatically expanded under Obama. The weapon was called Stuxnet. It was a computer worm — arguably the most precisely engineered piece of malware ever created at the time — and it was designed to do one specific thing: find the Siemens programmable logic controllers running Iran’s centrifuges at Natanz, tell those centrifuges to spin at speeds that would tear themselves apart, and simultaneously report to operators that everything was fine.
Think about that engineering achievement for a moment. This wasn’t a virus that crashed computers or stole passwords. It was a weapon that caused physical machinery to destroy itself while lying to the people watching the dials. It was deployed as early as 2007. By the time it was fully operational in 2009–2010, it had destroyed roughly a thousand centrifuges — roughly ten percent of Iran’s enrichment capacity — without a single conventional weapon being fired.
In July 2013, Edward Snowden confirmed what most analysts already suspected: the United States and Israel built Stuxnet together.
Here’s what nobody in the Washington policy corridor wanted to say out loud: Iran is an advanced engineering society. They have nuclear physicists. They have computer scientists. When something hits your infrastructure that is technically extraordinary, you don’t just clean it up and move on. You study it. You reverse-engineer it. You learn from it.
Iran enrolled in the American curriculum. And they were excellent students.
The proof came fast.
THE ANSWER: IRAN’S CYBER RETALIATION — A COMPLETE RECORD
2009: Before Stuxnet, The First Test
Before the centrifuges started destroying themselves and before Iran knew what was coming for it, Tehran was already running a cyber playbook against its own people.
The 2009 Green Revolution — the mass protests against Mahmoud Ahmadinejad’s stolen election — gave the IRGC its first live-fire exercise in cyber-enabled repression. A group calling itself the Iranian Cyber Army defaced Twitter’s homepage at a moment when Twitter had become the organizational central nervous system of the protest movement. Opposition websites were flooded with traffic attacks timed precisely to protest mobilization calls. Government critics were surveilled with malware disguised as documents about upcoming demonstrations.
The most technically significant move: an Iranian hacker breached Dutch security company DigiNotar and fraudulently obtained encryption certificates for Google. This gave Tehran the ability to intercept and read the Gmail communications of virtually every Iranian Gmail user — the entire domestic encrypted email infrastructure compromised through one breach of a certificate authority most people had never heard of. One entry point. Total surveillance coverage.
They learned two things from 2009. First, cyber tools are extraordinarily effective at disrupting organized political opposition. Second, the West was barely watching.
2011–2013: You Could Not Access Your Bank. Iran Did That.
After Stuxnet, Iranian cyber operations stopped being improvised and became structural. The IRGC and the Ministry of Intelligence began investing in offensive cyber as formal doctrine — a way to retaliate against adversaries without triggering a conventional military response. Asymmetric warfare by keyboard.
Starting in September 2012, a group calling itself “Izz ad-Din al-Qassam Cyber Fighters” launched what they framed publicly as a protest against an anti-Islam YouTube video. The name was a cover. The NSA’s signals intelligence revealed it was retaliation for Stuxnet, and senior Iranian officials were directly aware of the campaign.
The real name for what they were doing was Operation Ababil — and if you tried to log into your Bank of America account or Wells Fargo account or JPMorgan account in late 2012 or early 2013 and couldn’t get in, this is why.
They targeted 46 major U.S. financial institutions. Bank of America. JPMorgan Chase. Wells Fargo. Citigroup. Capital One. PNC. The New York Stock Exchange. They generated traffic volumes exceeding 100 gigabits per second — to put that in plain terms, they pointed more internet traffic at those banks’ websites than the banks’ servers could possibly handle. The websites went down. Customers were locked out. The campaign ran in coordinated waves for eight months, rotating targets to evade defensive measures as each bank deployed them.
It cost Western banks millions of dollars in remediation. Seven Iranian nationals contracted by the IRGC were eventually indicted by the Department of Justice. That indictment came in March 2016 — nearly four years after the attacks began.
Four years. Iran conducted an eight-month sustained attack on the American financial sector, and the legal system’s response lagged by four years.
2012: 35,000 Computers. Gone in Hours. Saudi Aramco.
While the banks were getting hammered, Iran deployed the weapon that would define its cyber doctrine for the next decade.
Shamoon is a wiper. Not ransomware — ransomware wants your money and gives your files back. Shamoon wants nothing except to destroy. It overwrites files. Then it overwrites the master boot record — the part of a hard drive that tells a computer how to start. Then the machine is dead. No recovery. No restoration. Dead.
In August 2012, Shamoon hit Saudi Aramco. Saudi Aramco, for context, is responsible for roughly 10 percent of the world’s oil supply. The attack began with a single phishing email to a single Aramco technician who clicked a single malicious link. That was the only human error required. Shamoon spread across the network and destroyed 35,000 computers in a matter of hours. The company reportedly had to fall back on typewriters and fax machines for weeks while IT teams worked to restore operations manually. An image of a burning American flag replaced the data on every wiped machine.
A companion attack simultaneously hit RasGas, Qatar’s natural gas company.
The entire global energy infrastructure of two major Gulf producers, disrupted by one email click.
Shamoon came back in waves. In November 2016 and January 2017, updated versions hit Saudi government ministries — the General Authority of Civil Aviation, the Ministry of Labor, the Saudi Central Bank. In the second wave, the image overwriting the deleted files had changed. It was now a photograph of Alan Kurdi — the three-year-old Syrian refugee child whose drowned body on a Turkish beach had become an international symbol of the refugee crisis. The hackers understood psychological operations. They weren’t just destroying data. They were making a statement about why.
2013: A Dam Outside New York
People remember Stuxnet as the moment cyber weapons could target physical infrastructure. People forget that Iran turned around and ran the same play on American soil.
An Iranian hacker employed by a company contracted by the IRGC gained remote access to the supervisory control and data acquisition system — SCADA, the software that runs industrial equipment — of the Bowman Avenue Dam in Rye, New York. The access gave him visibility into the dam’s water levels, gate positions, and operational status. He could see what the dam was doing. He was positioned to control it.
The only reason the gate wasn’t opened was that it had been manually disconnected for maintenance. Luck. That is the margin between a reconnaissance operation and a flooded New York suburb.
The Department of Justice indicted the actor in 2016. By then, the demonstrated capability — remote access to American water infrastructure via SCADA systems — had been confirmed to everyone paying attention. Including every other adversary.
Simultaneously, the Mabna Institute campaign quietly began. A group of IRGC-linked hackers posing as a legitimate Iranian company spent four years — 2013 to 2017 — systematically stealing intellectual property from 144 American universities, 176 universities across 21 other countries, 47 private companies, the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, and UNICEF. Thirty-one terabytes of academic research, defense-relevant technical data, and government documents. Gone. The DOJ indicted nine Iranians in 2018 — a year after the campaign ended. The gap between Iran being inside these institutions and anyone knowing about it was four years.
Four years is a theme with Iranian cyber operations. They’re not in a hurry.
2014: The Casino Owner Who Made a Nuclear Threat
This entry almost reads as satire but it happened.
The late Sheldon Adelson, owner of the Las Vegas Sands Corporation, had publicly suggested that the United States should detonate a nuclear weapon in the Iranian desert as a negotiating demonstration. Iranian hackers heard him. In February 2014, they destroyed the Sands Corporation’s network infrastructure — wiping hard drives, killing phone lines, taking down communications systems. The U.S. Director of National Intelligence directly attributed the attack to the Iranian government in congressional testimony.
This was not strategic infrastructure. This was a targeted, personal punishment for a specific statement made by a specific person. Iran was demonstrating that offensive cyber capability wasn’t just for geopolitical conflicts. It was also a personal enforcement mechanism. Say something they don’t like, and they will come through your network and take everything you built.
2017: Nearly an Explosion at a Saudi Petrochemical Plant
In August 2017, Iranian-linked hackers conducted a cyberattack against a Saudi petrochemical plant that attempted something that had never been done before: they tried to use malware to directly cause a physical explosion.
The malware, later called TRITON or TRISIS, targeted the plant’s Safety Instrumented Systems — the fail-safe controls specifically designed to prevent catastrophic industrial accidents. If a reactor pressure gets too high, the SIS is what stops the plant from blowing up. TRITON was designed to disable those safety systems and force the plant into a condition that would trigger an explosion.
It failed. A bug in the malware caused the safety systems to detect the intrusion and shut down operations before the physical sabotage could execute. Investigators described the discovery as one of the most dangerous pieces of malware ever found. The intent was explicit and documented: this was an attempt to kill people and destroy infrastructure via cyberspace.
That same year, APT35 — Iran’s premier social engineering group, which goes by approximately a dozen names including Charming Kitten, Magic Hound, and Phosphorus — hacked HBO and leaked Game of Thrones scripts while demanding a multimillion-dollar ransom. Less immediately dangerous than trying to blow up an oil facility, certainly, but useful data: Iran’s cyber apparatus was now running operations ranging from attempted industrial sabotage to celebrity intellectual property extortion. The portfolio had diversified.
Also in 2017: Russian intelligence service Turla — FSB-linked — was caught secretly piggybacking on Iranian APT infrastructure. The Russians were using OilRig’s (APT34’s) compromised servers as launchpads to run their own intelligence operations in the Middle East and the United Kingdom. The Iranians were being used as unwitting proxies by Moscow. Whether this was a pure exploitation or involved any degree of coordination is still debated. The takeaway is that Iran had built infrastructure significant enough that Russia considered it worth stealing access to.
2018: The Universities, the Midterms, and the Ransomware
In December 2018, the Department of Justice indicted two Iranian nationals for a ransomware attack that had paralyzed Atlanta’s city government in March of that year. The attack was SamSam ransomware — it encrypted the city’s systems and demanded payment to restore them. Atlanta’s municipal government was effectively offline for weeks. Courts couldn’t process cases. The city couldn’t collect water bill payments. Public services across one of America’s major cities ground down because two Iranians encrypted their servers.
The same year, three major Iranian disinformation operations were exposed, including one that had been running for six years under the name “Ayatollah BBC” — a network of fake Western-looking news sites designed to spread Iranian regime narratives while appearing to be independent outlets. The logic is identical to what Russia runs through GRU-linked media networks. The architecture is the same. The playbook transfers.
Also in 2018: Germany’s domestic intelligence service formally documented growing Iranian cyber activity targeting German government institutions, dissidents, the defense sector, the aerospace industry, and petrochemical companies. Iran wasn’t a regional problem. It was a global one.
2019: 2,700 Attempts in 30 Days. One Group. Your Email.
In a 30-day window between August and September 2019, APT35 — Charming Kitten, the IRGC’s social engineering and surveillance arm — made 2,700 attempts to access targeted email accounts, per Microsoft’s Threat Intelligence Center.
To be clear about who they were targeting: academics, journalists, government officials, think-tankers, human rights activists, and dissidents. People who write and think about Iran for a living. People who cover national security. People who criticize the regime publicly.
They weren’t brute-forcing random accounts. They were methodically working through a curated target list, running elaborate social engineering campaigns months in advance — fake conference invitations, fake academic collaboration offers, fake journalist interview requests impersonating actual reporters from CNN, The Wall Street Journal, and Deutsche Welle — before delivering the credential-harvesting payload. Building trust before stealing access. This is not a script kiddie operation. This is a sustained, well-resourced, patient intelligence collection program.
In March 2019, Microsoft seized 99 DNS domains operated by Iranian state hackers to disrupt the infrastructure. Iran rebuilt. They always rebuild.
2020: They Stole Your Vote. Or Tried To.
The 2020 U.S. election was the most directly targeted American democratic process by Iran to date.
Iran feared a second Trump term. Trump had killed Qasem Soleimani in January 2020, withdrawn from the nuclear deal, and imposed crushing sanctions. A Biden administration meant potential re-engagement. So Iran intervened.
Iranian actors sent threatening emails to Democratic voters impersonating the Proud Boys, apparently attempting to create conflict and suppression. They created and distributed a video falsely claiming widespread voter fraud in U.S. election systems. APT42 (Charming Kitten’s close cousin) targeted both the Trump and Biden campaign staffs for credential theft. Compromised materials from the Trump campaign were later passed to media outlets in what appeared to be a deliberate influence operation — steal the material, then shop it to journalists.
That same year, IBM’s X-Force team discovered over 40 gigabytes of Charming Kitten operational data — including training videos of IRGC operatives demonstrating, step by step, how to hack email and social media accounts. The footage showed access to accounts belonging to U.S. Navy and Hellenic Navy personnel. Think about that: IBM stumbled onto the Iranian cyber program’s internal training library. You can watch their tutorial videos. The sophistication on display — the patience, the methodology, the tradecraft — is not the work of amateurs.
2022: Iran Attacks a NATO-Adjacent Country. Almost Nobody Notices.
In July 2022, Iranian state hackers attacked the Albanian government. Albania — a NATO member since 2009.
The attack was not impulsive. Iranian actors had quietly obtained initial access to Albanian government networks fourteen months earlier, running silent for over a year, collecting email traffic, conducting reconnaissance, mapping the environment. Then in July 2022, they deployed ransomware-style file encryption and disk-wiping malware simultaneously, destroying data and knocking government websites and services offline. The desktop wallpaper on every infected machine was replaced with an anti-Mujahideen-e-Khalq message — Albania had given asylum to the MEK, an Iranian dissident group. This was political retaliation delivered through cyberspace.
Albania broke off diplomatic relations with Iran. The U.S., UK, and EU confirmed Iranian state responsibility. Then, in September 2022 — apparently in retaliation for the public attribution — Iran attacked Albania again.
Also in 2022: Iranian hackers targeted Boston Children’s Hospital, per FBI Director Christopher Wray. Australian infrastructure targeted. Turkey’s cyber networks hit. U.S. and UK officials issued joint warnings. Iranian transnational cyber operations had become a near-constant background condition of global digital infrastructure.
2023: They’re in Your Water.
CyberAv3ngers — an IRGC Cyber-Electronic Command group that had been presenting itself as pro-Palestinian hacktivists — hit multiple U.S. water treatment facilities.
The technique was almost embarrassingly simple. Unitronics programmable logic controllers — Israeli-made hardware widely used in water and wastewater systems — ship with default passwords. CyberAv3ngers used those default passwords to log into internet-connected water treatment equipment at facilities across the United States. They targeted Israeli-made hardware specifically. The targeting itself was the message: we can reach into American municipal infrastructure and we chose this equipment to make a point about Israel.
The U.S. Treasury Department eventually sanctioned six IRGC-CEC officials who had directed the operation. The fiction that these were independent hacktivists dissolved. They were state actors with government paychecks and military chain of command.
Simultaneously, German domestic intelligence issued formal warnings about Iranian agents conducting “concrete spying attempts” on Iranian activists across Europe. Iranian transnational repression — the practice of reaching across borders to intimidate, surveil, and threaten diaspora communities and regime critics — had become a documented, ongoing program operating on European soil.
2024: They Hit Both Presidential Campaigns. And Your Water System. Again.
In a second round, CyberAv3ngers deployed custom malware — later named IOCONTROL — to remotely control U.S. and Israel-based water and fuel management systems. This wasn’t reconnaissance anymore. This was active control capability over physical infrastructure.
APT42 simultaneously targeted both the Trump and Biden campaign staffs for credential theft. In the Trump operation, they succeeded in exfiltrating materials and passed them to journalists — a complete intelligence operation from access acquisition to media placement. The FBI and CISA publicly attributed both campaign targeting operations to Iran. A 59-page intelligence assessment found Charming Kitten (APT42) specifically targeting Trump campaign communications.
Also: Iran ran documented influence operations in Israeli legislative and municipal elections in 2022 and 2024, running fake social media accounts, generating discord, and attempting to shape electoral outcomes in a foreign democracy.
2025: The AI Upgrade and the War That Preceded the War
Through the first half of 2025, Iranian APT groups integrated generative AI into their operations. This is not abstract. APT42 is now running what researchers call “RedKitten” operations — AI-generated, hyper-personalized social engineering campaigns that can construct convincing fake personas, maintain coherent months-long correspondence, and adapt in real time to the target’s responses. The fake journalist writing to you for an interview request now writes better prose than some actual journalists.
In June 2025, a twelve-day Iran-Israel conflict triggered the largest coordinated Iranian hacktivist mobilization on record. Researchers analyzed over 250,000 Telegram messages from 178+ hacktivist and proxy groups. The analysis found that attack timing, target selection, and the sharing of vulnerability information and attack scripts across groups showed clear orchestration — not organic grassroots activity. The groups were running coordinated operations under state direction while maintaining the public posture of independent actors.
By late 2025, MuddyWater — Iran’s highest-volume APT actor, linked to the Ministry of Intelligence — deployed a custom backdoor called Phoenix against more than 100 government entities and international organizations across the Middle East and North Africa in a single spear-phishing campaign. In October alone.
The pre-positioning for what was coming had been underway for years.
2026: The Electronic Operations Room
On February 28, 2026 — the same day Operation Epic Fury began destroying Iranian military infrastructure from the air — Iran stood up what it called the “Electronic Operations Room.” A formal coordination structure pulling together 60-plus hacktivist groups and proxy cyber actors, including pro-Russian elements. Over 150 hacktivist incidents recorded in the first 24 hours. Iran’s internet dropped to between one and four percent connectivity — the combined effect of Israeli cyber operations described by multiple analysts as the largest cyberattack in history, directed at Iran’s own digital infrastructure to blind regime communications and fuel internal instability.
But Iran’s cyber apparatus isn’t housed only in Tehran. It never was. The operational cells, the pre-positioned malware in foreign infrastructure, the hacktivist proxy network — these exist outside Iran’s borders. The Electronic Operations Room activated them all.
Handala — Iran’s most prominent MOIS-linked proxy persona — claimed breaches of Sharjah National Oil Corporation and Israel Opportunity Energy, reportedly exfiltrating 1.3 terabytes of oil contracts and financial data. CISA issued an emergency advisory to all U.S. critical infrastructure operators warning of elevated Iranian cyber threat. Symantec confirmed Seedworm (MuddyWater) actively inside U.S. infrastructure and defense supply chain networks. APT33 deployed Tickler and SHAPESHIFT wipers against U.S. aerospace and petrochemical targets. Manufacturing and transportation sectors showed a systematic surge in attack activity.
And Handala sent death threat emails to Iranian-American and Iranian-Canadian influencers — critics of the regime — claiming to have sent their home addresses to physical operatives in the United States and Canada. The digital infrastructure as delivery mechanism for real-world violence. The keyboard as the first weapon, the operative on the ground as the second.
THE APPARATUS BEHIND IT
This is not a collection of lone wolves. This is a structured, institutionally backed cyber warfare program operating under two competing bureaucracies that share infrastructure and occasionally step on each other’s operational territory.
The IRGC — the Islamic Revolutionary Guard Corps — reports directly to the Supreme Leader, bypassing elected government entirely. Its cyber arm, the IRGC-CEC, runs the aggressive, ideologically driven operations: the ones that target American water systems, the ones that tried to blow up Saudi petrochemical plants, the ones that punish individual critics. APT33, APT35, APT42, CyberAv3ngers, and most of the proxy hacktivist network answer to this chain.
The MOIS — the Ministry of Intelligence — reports to the President. It runs Iran’s traditional foreign espionage: the long-access-time infiltrations, the sustained credential collection, the patient intelligence operations. OilRig (APT34), MuddyWater, and Handala sit primarily in this lane.
These two institutions compete as much as they coordinate. They have different masters, different mandates, and different operational tempos. Understanding this matters because it means Iranian cyber operations are not a single coordinated program — they are two parallel programs with overlapping targets and occasionally overlapping infrastructure that sometimes run independent of each other.
The proxy hacktivist layer sits above both of them as plausible deniability. Izz ad-Din al-Qassam Cyber Fighters were “hacktivists.” CyberAv3ngers were “hacktivists.” Homeland Justice were “hacktivists.” In every case, Treasury sanctions or DOJ indictments later confirmed state direction. The performance of independent ideological motivation is baked into the operational design. When you see an Iranian-adjacent hacktivist group claiming credit for something, start your analysis from the assumption that there are government paychecks in the picture.
THE TECHNIQUE — HOW THEY ACTUALLY DO IT
For readers who want to understand what this looks like at the operational level:
The front door is almost always either spear-phishing or password spraying. Spear-phishing means a carefully crafted email designed to look like it comes from someone you trust, carrying either a malicious attachment or a link to a credential-harvesting page. For APT35 and APT34, the “carefully crafted” part involves months of reconnaissance and relationship-building — fake personas developed over time, tailored to the specific target’s professional world. Password spraying means running a common password against hundreds of thousands of accounts simultaneously, staying below detection thresholds, and winning through volume.
Once they’re in, they live off the land. PowerShell — already installed on every Windows machine — is the single most common execution tool across Iranian APT groups. They use native Windows administrative tools, the same things your IT team uses, to move laterally through networks, escalate privileges, and harvest credentials. They avoid dropping custom malware until later in the operation because malware can be detected and signature-matched. Administrative tools don’t get flagged the same way.
For command-and-control — the communications channel between the attacker and their implants in your network — they hide inside cloud services. APT34 uses OneDrive and Exchange Online. APT35 uses Dropbox, Google Drive, and IPFS. MuddyWater uses the Telegram API. Your security tools see legitimate traffic to Microsoft’s servers and wave it through. The malicious commands are riding inside.
MFA is not the wall people think it is. APT35’s credential harvesting kits intercept multi-factor authentication codes in real time. You enter your password and your MFA code into a fake login page that looks exactly like the real one. The kit uses your credentials immediately, before the session expires, to log into the real service and start a legitimate session under your identity. You’ve done everything right and they’re still in.
THE LINE AT THE BOTTOM
Every news cycle about Iran focuses on the thing with the contrail. The drone. The missile. The satellite image of the crater. That’s the war you can photograph.
The war you cannot photograph has been running continuously since at least 2009. It has been inside American banks, American water systems, American universities, American political campaigns, American municipal governments, and American critical infrastructure. It has attempted to physically destroy Saudi oil facilities, nearly succeeded in blowing up a petrochemical plant, and successfully wiped the hard drives of 35,000 computers belonging to one of the most important energy companies on earth. It has attacked a NATO member country. It has threatened diaspora journalists with death, including providing their home addresses to what it claims are physical operatives.
The United States and Israel handed Iran the curriculum in 2007 when they deployed Stuxnet. Iran studied the lesson carefully, built the apparatus, recruited the operators, and has been running the program ever since.
The missiles flying across the Middle East right now are the visible part of this conflict. The part that has been ongoing for sixteen years — the part that is, at this moment, inside infrastructure you depend on — doesn’t show up on a damage assessment report.
It shows up later. Usually when it’s already too late.
Chris Sampson is Editor-in-Chief of NatSecMedia, host of The Wire Tap, and author of Hacking ISIS. He has lived in Ukraine since January 31, 2022.
OPERATION OLYMPIC GAMES / STUXNET
Falliere, Nicolas, Liam O Murchu, and Eric Chien. W32.Stuxnet Dossier, Version 1.4. Cupertino, CA: Symantec Security Response, February 2011. https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-044.pdf
Sanger, David E. Confront and Conceal: Obama’s Secret Wars and Surprising Use of American Power. New York: Crown Publishers, 2012.
Sanger, David E. “Obama Order Sped Up Wave of Cyberattacks Against Iran.” New York Times, June 1, 2012. https://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html
OPERATION ABABIL — BANK DDoS (2012–2013)
U.S. Department of Justice, Office of Public Affairs. “Manhattan U.S. Attorney Announces Charges Against Seven Iranians for Conducting Coordinated Campaign of Cyber Attacks Against U.S. Financial Sector.” Press release, March 24, 2016. https://www.justice.gov/usao-sdny/pr/manhattan-us-attorney-announces-charges-against-seven-iranians-conducting-coordinated
Federal Bureau of Investigation. “Iranians Charged with Hacking U.S. Financial Sector.” FBI News, March 24, 2016. https://www.fbi.gov/news/stories/iranians-charged-with-hacking-us-financial-sector
Federal Bureau of Investigation. “Iranian DDoS Attacks” [Wanted Poster — Seven Defendants]. Updated 2016. https://www.fbi.gov/wanted/cyber/iranian-ddos-attacks
SHAMOON / SAUDI ARAMCO (2012, 2016–2017)
Kaspersky Lab Global Research and Analysis Team. “From Shamoon to StoneDrill: Wipers Attacking Saudi Organizations and Beyond.” Securelist, March 6, 2017. https://securelist.com/from-shamoon-to-stonedrill/77725/
Kaspersky Lab. From Shamoon to StoneDrill: Wipers Attacking Saudi Organizations and Beyond [Full Technical Report]. Moscow: Kaspersky Lab, 2017. https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180722/Report_Shamoon_StoneDrill_final.pdf
Perlroth, Nicole, and Quentin Hardy. “Bank Hacking Was the Work of Iranians, Officials Say.” New York Times, January 8, 2013. https://www.nytimes.com/2013/01/09/technology/online-banking-attacks-were-work-of-iran-us-officials-say.html
The Register. “Hack on Saudi Aramco Hit 30,000 Workstations, Oil Firm Admits.” The Register, August 29, 2012. https://www.theregister.com/2012/08/29/saudi_aramco_malware_attack_analysis/
BOWMAN AVENUE DAM / RYE, NEW YORK (2013)
U.S. Department of Justice. “Manhattan U.S. Attorney Announces Charges Against Seven Iranians for Conducting Coordinated Campaign of Cyber Attacks Against U.S. Financial Sector.” Press release, March 24, 2016 [same indictment covers dam intrusion]. https://www.justice.gov/usao-sdny/pr/manhattan-us-attorney-announces-charges-against-seven-iranians-conducting-coordinated
MABNA INSTITUTE — UNIVERSITY HACKING (2013–2017)
U.S. Department of Justice, Southern District of New York. “Nine Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps.” Press release, March 23, 2018. https://www.justice.gov/usao-sdny/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic
Federal Bureau of Investigation. “Iranian Mabna Hackers” [Wanted Poster]. FBI.gov. https://www.fbi.gov/wanted/cyber/iranian-mabna-hackers
Federal Bureau of Investigation. “State-Sponsored Cyber Theft.” FBI News, March 23, 2018. https://www.fbi.gov/news/stories/nine-iranians-charged-in-hacking-scheme-032318
U.S. Department of the Treasury, Office of Foreign Assets Control. “Treasury Sanctions Iranian Cyber Actors for Malicious Cyber-Enabled Activities Targeting Hundreds of Universities.” Press release, March 23, 2018. https://home.treasury.gov/news/press-releases/sm0332
LAS VEGAS SANDS CORPORATION (2014)
Perlroth, Nicole, and Elizabeth Bumiller. “Hackers Took Aim at Las Vegas Sands, Experts Say.” New York Times, December 11, 2014. https://www.nytimes.com/2014/12/12/technology/hackers-took-aim-at-las-vegas-sands-experts-say.html
Foundation for Defense of Democracies. “Evolving Menace: Iran’s Use of Cyber-Enabled Economic Warfare.” FDD.org, November 6, 2018. https://www.fdd.org/analysis/2018/11/06/evolving-menace/ [Contains DNI Clapper attribution citation.]
TRITON/TRISIS — SAUDI PETROCHEMICAL PLANT (2017)
Johnson, Blake, Dan Caban, Marina Krotofil, Dan Scali, Nathan Brubaker, and Christopher Glyer. “Attackers Deploy New ICS Attack Framework ‘TRITON’ and Cause Operational Disruption to Critical Infrastructure.” Mandiant Threat Research, December 14, 2017. https://www.mandiant.com/resources/attackers-deploy-new-ics-attack-framework-triton
Dragos, Inc. TRISIS Malware: Analysis of Safety System Targeted Malware. Hanover, MD: Dragos, December 2017. https://www.dragos.com/wp-content/uploads/TRISIS-01.pdf
Greenberg, Andy. “Triton Is the World’s Most Murderous Malware, and It’s Spreading.” MIT Technology Review, March 5, 2019. https://www.technologyreview.com/2019/03/05/103328/cybersecurity-critical-infrastructure-triton-malware/
Higgins, Kelly Jackson. “Triton/Trisis Attack Was More Widespread Than Publicly Known.” Dark Reading, January 14, 2019. https://www.darkreading.com/cyberattacks-data-breaches/triton-trisis-attack-was-more-widespread-than-publicly-known
ATLANTA RANSOMWARE — SamSam (2018)
U.S. Department of Justice. “Two Iranian Men Indicted for Deploying Ransomware to Extort Hospitals, Municipalities, and Public Institutions, Causing Over $30 Million in Losses.” Press release, November 28, 2018. https://www.justice.gov/opa/pr/two-iranian-men-indicted-deploying-ransomware-extort-hospitals-municipalities-and-public
Federal Bureau of Investigation. “Ransomware Suspects Indicted.” FBI News, November 28, 2018. https://www.fbi.gov/news/stories/iranian-ransomware-suspects-indicted-112818
Federal Bureau of Investigation. “SamSam Subjects” [Wanted Poster — Savandi and Shah Mansouri]. FBI.gov. https://www.fbi.gov/wanted/cyber/samsam-subjects
CHARMING KITTEN — 2,700 CREDENTIAL ATTEMPTS (2019)
Burt, Tom. “New Steps to Protect Customers from Hacking.” Microsoft On the Issues, March 27, 2019. https://blogs.microsoft.com/on-the-issues/2019/03/27/new-steps-to-protect-customers-from-hacking/
Burt, Tom. “Recent Cyberattacks Require Us All to Be Vigilant.” Microsoft On the Issues, October 4, 2019. https://blogs.microsoft.com/on-the-issues/2019/10/04/recent-cyberattacks-require-us-all-to-be-vigilant/ [Contains the 2,700 attempts / 30-day figure.]
IBM X-FORCE — 40GB OPERATIONAL DATA LEAK (2020)
Wikoff, Allison, and Richard Emerson. “New Research Exposes Iranian Threat Group Operations.” Security Intelligence (IBM), July 16, 2020. https://securityintelligence.com/posts/new-research-exposes-iranian-threat-group-operations/
IRAN ELECTION INTERFERENCE — 2020
Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency. “Iran-Based Threat Actor Exploits VPN Vulnerabilities.” Joint Advisory, October 30, 2020. https://www.cisa.gov/news-events/alerts/2020/10/30/iran-based-threat-actor-exploits-vpn-vulnerabilities
Sanger, David E., and Nicole Perlroth. “Iran Sent Fake Proud Boys Emails to Intimidate Democratic Voters.” New York Times, October 21, 2020. https://www.nytimes.com/2020/10/21/us/politics/iran-election-emails.html
ALBANIA — NATO MEMBER ATTACK (2022)
Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. “Iranian State Actors Conduct Cyber Operations Against the Government of Albania.” Joint Advisory AA22-264A, September 21, 2022. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-264a
CyberAv3ngers — U.S. WATER SYSTEMS (2023–2024)
Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Environmental Protection Agency, and Israel National Cyber Directorate. “IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities.” Joint Advisory, December 1, 2023. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
U.S. Department of the Treasury, Office of Foreign Assets Control. “Treasury Sanctions IRGC-Affiliated Actors Responsible for Cyberattacks Against U.S. Critical Infrastructure.” Press release, February 2, 2024. https://home.treasury.gov/news/press-releases/jy2064
IOCONTROL MALWARE (2024)
Claroty Team82. “IOCONTROL: OT/IoT Cyberweapon Used by Iran-Affiliated Threat Actors for Critical Infrastructure Attacks.” Claroty, December 12, 2024. https://claroty.com/team82/research/iocontrol-otiot-cyberweapon-used-by-iran-affiliated-threat-actors
APT42 — CAMPAIGN TARGETING (2024)
Google Threat Analysis Group and Mandiant. “Iranian Backed Group Targets Israelis, Opposition Figures and U.S. Presidential Campaigns in Multi-Country Campaign.” Google TAG / Mandiant, August 14, 2024. https://cloud.google.com/blog/topics/threat-intelligence/apt42-charms-cons-compromises
2026 — OPERATION EPIC FURY / ELECTRONIC OPERATIONS ROOM
American Banker. “War in Iran Brings Cyber Frontline to U.S. Banks.” American Banker, March 4, 2026. https://www.americanbanker.com/news/war-in-iran-brings-cyber-frontline-to-u-s-banks
Cybersecurity and Infrastructure Security Agency. [Emergency Advisory — Elevated Iranian Cyber Threat, February–March 2026.]
https://www.cisa.gov
[Specific advisory number to be confirmed upon CISA publication.]
BACKGROUND / INSTITUTIONAL STRUCTURE
Congressional Research Service. Iran: Internal Politics and U.S. Policy and Options. CRS Report IF11406. Washington, DC: Congressional Research Service, updated periodically. https://crsreports.congress.gov/product/pdf/IF/IF11406
United States Institute of Peace. Iran Primer. Washington, DC: USIP.
https://iranprimer.usip.org
Carnegie Endowment for International Peace. Iran Cyber Capabilities. Washington, DC: Carnegie Endowment. https://carnegieendowment.org/research/2022/11/iran-cyber-capabilities



Excellent diving piece. The Meat of the “Other” war that we tend to ignore. Internet infrastructure's attacks we face daily & and issue the global community is fighting 💪 Great Piece👏
Another fascinating and overwhelming article for me to contemplate. As a functionally illiterate IT person, at least beyond surfing and scrolling this stuff is amazing. It's like watching the ocean . You see and feel the power but just can't comprehend its vastness or complexity.
On another note, I would like to read the comments of other people. A widow at the top of this page says there are 13 comments but I can't see them.