
Publication date: 5 August 2026. This assessment reflects intelligence available as of this date; references to “the time of writing” denote early August 2026. The reporting window spans the March 2026 escalation through the 28 July 2026 incidents.
The confrontation over the Strait of Hormuz has reinforced a pattern CYFIRMA analysts have tracked throughout the current Iran–U.S. cycle: the most persistent activity is unfolding in the cyber domain, no matter the status of the kinetic exchanges that dominate headlines. Periods of diplomacy and ceasefire have not coincided with reduced Iran-linked cyber operations, as the digital domain offers Tehran calibrated, semi-deniable space it can leverage during periods of negotiations.
Iran-aligned actors are treating any lull in kinetic operations as an opportunity to pre-position within critical infrastructure. They are also seeking to impose costs on critical infrastructure across the Gulf Cooperation Council (GCC), the United States, Israel, their allies, and even neutral states such as Qatar. The strategically significant threat is concentrated in a small number of state and state-fronted groups with demonstrated operational-technology (OT), wiper, and access-brokering capability. The much larger hacktivist ecosystem generates volume and noise but has limited durable impact.
For infrastructure operators, defence suppliers, financial institutions, and multinationals with Gulf exposure, the operational takeaway is that a ceasefire in the physical domain should not be read as de-escalation in the cyber domain. Network integrity – particularly of internet-exposed OT, edge devices, and identity systems – is now the primary theatre of resilience. These assessments are based on the intelligence available at the time of writing and are subject to change as the situation develops; they should be read alongside each organisation’s own security controls and monitoring.

Despite large-scale hostilities between Iran and the United States being largely paused at the time of writing, the status of the Strait of Hormuz remained contested and the truce was repeatedly punctuated by maritime and missile incidents and periods of lower-intensity fighting. For the purposes of cyber risk assessment, three features of this environment matter:
First, control of the Strait is Tehran’s principal source of economic leverage and of conflicting visions for post-war order in the Middle East. Iran has signalled that if its own oil exports are constrained, it intends to impose costs on the exports of others – either by blockade or by cyber attack. This should be read as an intent to use cyber operations as an economic-coercion tool, which raises the risk to energy shipping, port, and terminal operators regardless of the current tempo of kinetic operations.
Second, the threshold logic favours action in the cyber domain during lulls in kinetic fighting. Direct kinetic strikes on shipping lanes or energy infrastructure risk a decisive conventional response from the still heavily deployed U.S. forces. Cyber operations offer a lower-threshold, semi-deniable alternative for calibrated escalation during ceasefire or negotiation periods. This dynamic makes cyber the preferred vector precisely when diplomacy appears to be advancing.
Third, neutrality does not confer immunity. The extension of reconnaissance activity to Qatari LNG infrastructure – a mediator state – indicates that targeting is driven by leverage over the global economy and signalling value, not solely by the perceived hostility towards the Islamic Republic. This materially broadens the population of at-risk operators across the GCC and beyond the immediate region.

Iranian cyber activity is widely assessed not to be unified under a single command but operates as a layered ecosystem: IRGC intelligence and cyber-electronic organs, the Ministry of Intelligence and Security (MOIS/VAJA), contractor front companies, and hacktivist or “faketivist” personas coordinated by or aligned with those services (CISA/FBI joint fact sheet, 30 June 2025). Named APT groups map imperfectly across vendors and are frequently conflated – Handala, for example, is tracked variously as overlapping with Void Manticore, Banished Kitten, and Storm-0842.
Two structural features shape the risk. The first is a division of labour between long-dwell intelligence collection (IRGC-IO, MOIS/VAJA) and direct OT/ICS disruption (IRGC-CEC). The second is a handoff pattern in which stealthy access obtained for espionage is passed to a separate cluster for a destructive phase – the transition publicly reported between Scarred Manticore and Void Manticore is the reference case. Operationally, an intrusion that presents as routine espionage can be repurposed for sabotage with little warning, and defenders cannot assume that “quiet” access is benign. A full actor reference table is provided in Appendix A.
On June 17, U.S. President Donald Trump and Iranian President Masoud Pezeshkian signed separate copies of a memorandum of understanding mediated by Pakistan and Qatar. The agreement halted ongoing hostilities and offered immediate mutual benefits: shipping traffic through the Strait of Hormuz increased, global oil prices fell, and Washington granted Tehran a 60-day waiver on Iranian oil and petrochemical sales. However, conflicting interpretations of many negotiated points, chief among them the status of the Strait of Hormuz, highlight the difficult road toward a comprehensive final treaty.
Tehran’s public posture since the recent conflict suggests it does not regard capitulation to American pressure as necessary, citing its survival and continued leverage over the strait. While both capitals recognise the steep military and economic costs if the truce collapses, Tehran has signalled that it is not prepared to relinquish control over the Strait of Hormuz, and its leadership appears to view the approach of Washington as evidence that the U.S. administration is deeply reluctant to re-enter a broader war.
Meanwhile, Tehran has stated that it is only using the negotiations to buy time and resources, framing the war with the U.S. as essentially permanent. At the same time, U.S. Secretary of State Marco Rubio has toured the region and publicly pushed back on Iran deriving any revenue from the Strait of Hormuz, whether through tolls or under any other designation: Rubio also stated that the Gulf states have zero support for such fees, and warned that if Iran blocks the strait, the U.S. might return to war. Iranian officials have been sending contradictory messages on the status of the strait, while the actions of the Iranian Revolutionary Guards have been read by observers as a clearer signal of intent.
During Rubio’s visit, Oman and the International Maritime Organization (IMO) unveiled a new southern transit route through the Strait of Hormuz that hugs the Omani coastline, bypassing Iran. The Islamic Revolutionary Guard Corps (IRGC) Navy reacted swiftly and aggressively, declaring the Omani-IMO corridor prohibited and insisting that safe passage is only valid through Iran-designated transit channels.

Hours later, a Singapore-flagged container ship was struck by a projectile along the new southern route near Oman. This strike, publicly attributed by the U.S. to the IRGC, directly addressed Tehran’s core dilemma: either accept the Omani route and watch its primary geopolitical leverage evaporate, or contest it and risk violating the signed MOU. Tehran ultimately chose the latter; according to public reporting, both sides then traded strikes for roughly two weeks, during which the U.S. is reported to have struck Iranian coastal areas and infrastructure while Iran fired at ships sailing through the Strait of Hormuz and at American bases in the region. The current status of the fighting remains unclear, with the uneasy truce reportedly punctuated by sudden attacks such as the one on 28 July, when Iran was reported to have fired multiple ballistic missiles at a U.S. base in Jordan.
Iran’s approach is assessed to centre on preserving control over the Strait of Hormuz for as long as possible, in the expectation – reflected in statements from Iranian officials – that rising oil prices and declining energy reserves could eventually compel the U.S. administration to back down or accept a weaker deal.
Iranian decision-makers keep demonstrating they believe they still retain escalation options, including their slowly reconstituting cyber capabilities and the renewed disruption of the Bab al-Mandab Strait in the Red Sea by the Yemeni Houthis, who proclaimed a blockade of Saudi Arabia on July 20th. They also remember that previous disruptions to regional shipping contributed to higher oil prices, and they may calculate that energy markets remain a source of strategic leverage. Tehran has also made it clear that if its own oil exports are blocked, it will ensure other nations pay a price to export theirs, be it by way of de facto blockade in the Strait of Hormuz – or by cyber attacks.
Threat intelligence analysts identified active reconnaissance and targeted digital operations by Iran-aligned groups against liquefied natural gas (LNG) infrastructure at Ras Laffan and Mesaieed in Qatar – a country that stayed neutral in the conflict and served as a mediator between Tehran and Washington.
Ras Laffan is the largest single-site liquefied natural gas (LNG) export hub in the world, processing roughly 20% of global LNG supply, while Mesaieed hosts vital power, water, and petrochemical infrastructure. Cyber researchers have publicly assessed that these digital operations were heavily focused on network mapping, harvesting credentials, and “pre-positioning” inside plant networks. In hybrid operations, this digital reconnaissance is used to establish long-term access for potential destructive payloads (such as wiper malware) or to feed real-time targeting data for kinetic strikes.

In CYFIRMA’s assessment, the cyber probing at Ras Laffan and Mesaieed immediately preceded and accompanied the kinetic attacks during the escalation in early March. According to public reporting, drone and missile strikes on the complexes forced state-owned QatarEnergy to halt LNG production and declare force majeure on March 4, cutting off nearly 17% of Qatar’s export capacity and sending European and Asian gas benchmarks soaring. At the time of writing, Qatari authorities had extended force majeure on several further cargoes, bringing the total affected to 24 shipments through at least September, and barred further reductions in output and shipping capacity.
Attacking Qatari energy networks appears intended to serve as a direct warning to GCC nations, signalling that their critical civilian infrastructure – desalination plants, power grids, and LNG trains – remains vulnerable to non-kinetic disruption or sabotage if regional tensions escalate further. The operations against Ras Laffan and Mesaieed illustrate how cyber reconnaissance is integrated into modern energy warfare: digital intrusions are used to probe vulnerabilities, establish leverage, and pave the way for broader economic and physical disruption.
The White House is attempting to present Tehran with a binary choice: global economic integration and wealth (Path A), or continued destruction (Path B). The obstacle is structural – integration would benefit Iran as a country but not its ruling regime.
Analysts characterise the Iranian system as a revisionist theocracy that prioritises regime survival and revolutionary identity over citizens’ material prosperity, and that has historically treated economic integration as a threat to internal control rather than an opportunity to pursue.

Iran is assessed to be economically weakened and domestically unpopular – with protests reported even in areas seen as core regime constituencies – yet to have gained substantial geopolitical leverage through its demonstrated capacity to disrupt global energy markets, increasingly by cyber as well as kinetic means.
The war is assessed to have both destabilised and emboldened the regime in pursuit of the IRGC’s long-stated goal of reducing the U.S. military and political presence in the Middle East – an objective it now appears to treat as achievable in the near term rather than a distant aspiration. On this basis, CYFIRMA assesses that continued friction is likely and that any ceasefire may remain incomplete; as set out below, cyber activity linked to this conflict has continued regardless of the state of kinetic hostilities.
Even outside the shaky ceasefire in the Middle East, the traditional binary between “war” and “peace” has become an obsolete relic of the digital age. Today, the global landscape is defined by a nonstop, simmering conflict in the cyber and electromagnetic domains, operating outside the boundaries of declared hostilities. Global superpowers like the United States and China, alongside regional actors like Iran, are no longer just spying – they are actively pre-positioning disruptive capabilities deep within the critical networks of their opponents. From municipal water systems and civilian telecommunications to military command loops, the wires remain hot indefinitely. In this new reality of permanent attrition, the battlefield is everywhere, securing tactical dominance and embedding digital leverage years before a single conventional weapon is fired.

Silent Openers: According to statements by the U.S. military, Operation Epic Fury against Iran – and the raid on Caracas to capture President Maduro – began not with kinetic artillery but with coordinated, cross-domain strikes led by U.S. Space Command (SPACECOM) and U.S. Cyber Command (CYBERCOM), adapting a “layering effects” doctrine refined during Operation Absolute Resolve in Venezuela.
Pre-emptive Blinding: According to open-source reporting, non-kinetic tools jammed Iranian radars and severed communication links between command centres, airfields, and fighter jets before manned aircraft entered sovereign airspace.
Technical Necessity: Dominating the spectrum is mandatory for modern warfare; advanced precision-guided munitions (relying on GPS, lasers, or satellite navigation) face a high likelihood of failure if the electromagnetic domain is successfully contested.
Pattern of Life Infiltration: CYFIRMA assesses that the elimination of high-ranking Iranian regime figures was the culmination of long-term intelligence gathering. According to open-source reporting, Israeli intelligence is alleged to have spent years intercepting encrypted feeds from hacked Tehran traffic cameras to map the routines, home addresses, and internal structures of leadership security details. In CYFIRMA’s assessment, the mundane cyber architecture of everyday life can and will be weaponised.
Network Isolation as a Weapon: Open-source reporting indicates that, on the day of the kinetic strike, cyber forces disrupted mobile towers near the target compound, manipulating networks to make protection-detail phones appear “busy” and blocking incoming warnings.
Psychological Warfare: According to open-source reporting, Israel conducted targeted psychological operations, including threatening Telegram messages sent to thousands of IRGC and Basij members warning them they were under surveillance.
Asymmetric Propaganda & AI: In CYFIRMA’s assessment, to mask its weak military performance on the ground, Iranian state media deployed advanced AI, recycled footage, and fabricated claims of downing U.S. jets or striking naval vessels. Disinformation campaigns leveraged Western conspiracy theories (e.g., the “Epstein files”) to attack the legitimacy of U.S. and Israeli leadership.
Opportunistic Cyber Exploitation: Facing heavily defended military networks, decentralised Iranian actors (such as Handala, widely attributed to MOIS) pursue low-barrier, high-visibility civilian targets to impose indirect costs on the West. A parallel access-brokering economy compounds this risk: Fox Kitten (Pioneer Kitten), publicly attributed by FBI/CISA advisory AA24-241A, is reported to have harvested credentials for years from unpatched VPN and firewall appliances and sold the resulting domain-admin access to ransomware affiliates such as ALPHV/BlackCat and RansomHouse, blurring the line between state-linked espionage and for-profit cybercrime.
Representative claims (313 Team / Islamic Cyber Resistance in Iraq):



Screenshots of “313 Team” (Islamic Cyber Resistance in Iraq) claims, illustrating claim-making behaviour. Unverified by CYFIRMA; inclusion does not confirm impact. The group is classified as a decentralised proxy functioning as part of Iran’s broader, “asymmetric” cyber ecosystem – widely attributed to Iran’s Ministry of Intelligence and Security (MOIS) and to Shia militias in Iraq assessed to be backed by the IRGC.
Healthcare/Supply Chain Impact: A major data-wiping cyberattack – publicly attributed to the Handala Hack Team, which is assessed to be linked to Iran’s MOIS – targeted medical device manufacturer Stryker Corporation via its Microsoft Intune mobile-device-management platform on 11 March 2026, reportedly wiping over 200,000 devices across 79 countries, forcing 56,000 employees offline, and threatening hospital supply chains.
Doxxing of U.S. Troops: According to open-source reporting, a cyber collective assessed to be linked to Iran’s MOIS – consistent with the hack-and-leak playbook – leaked sensitive personal data (addresses, family details, shopping history) of over 2,300 American service members stationed in the Persian Gulf.
High-Profile Breaches: In late March 2026, the FBI acknowledged that malicious actors targeted the personal email account of Director Kash Patel; the Handala Hack Team claimed responsibility, and the Department of Justice has since publicly linked the group to Iran’s Ministry of Intelligence and Security.
Obsolete Boundaries: The traditional binary between “war” and “peace” has collapsed into a continuous, grey-zone struggle.
Explosion of Cyber Crime: According to open-source reporting, phishing and malware campaigns in the Gulf region have surged by roughly 130% since the conflict began, driven by a mix of state-sponsored operations and opportunistic cybercriminals exploiting wartime uncertainty. Israel’s National Cyber Directorate chief Brig. Gen. Yossi Karadi said Iranian cyber incidents against Israel rose from around 1,600 in June 2025 to some 4,800 in June 2026.
The Hot Wire Era: For global manufacturers, critical infrastructure, and defence contractors, the integrity of the network is now the primary theatre of survival: CyberAv3ngers, an OT-focused group publicly attributed to the IRGC, pivoted in 2026 to exploiting CVE-2021-22681, an unpatched authentication bypass in Rockwell Automation Logix controllers (CVSS 9.8), alongside Schneider Electric and Siemens PLCs across water, energy, and government-facility networks (CISA/FBI/EPA/DOE advisory AA26-097A, updated 22 July 2026). The era of the “clean ceasefire” is over; digital attrition continues unabated even when physical weapons fall silent.
Within this framework of sustained grey-zone pressure, Tehran is increasingly likely to weaponise its cyber capabilities as semi-deniable instruments of pressure directed not only at Washington, Israel and its closest allies, but also at the Gulf Cooperation Council (GCC) states to indirectly manipulate Washington. Recognising that direct kinetic assaults on shipping lanes or energy infrastructure risk triggering a devastating conventional response from the heavily deployed U.S. forces, Tehran treats the digital domain as the ideal vector for calibrated escalation during any period of ceasefire or negotiations.
By deploying sophisticated ransomware-as-a-service fronts, wiper malware, or disruptive operations against vulnerable municipal targets, desalination plants, and financial networks within the UAE, Saudi Arabia, or Oman, Tehran can inflict severe economic pain while maintaining just enough ambiguity to complicate attribution. This is not a hypothetical: CISA’s AA26-097A advisory documents confirmed 2026 disruptions to Water and Wastewater, Energy, and Government Services and Facilities entities from IRGC-linked PLC exploitation, and the destructive cluster assessed to be linked to MOIS (Void Manticore, Handala) has an established pattern of handing off access from espionage operations to wiper deployment.
Tehran’s actions and public statements by IRGC functionaries are assessed to indicate that the regime treats Western concessions less as a foundation for trust than as leverage to be used in a sustained campaign to reduce American influence in the Middle East.
This underlying reality ensures that any future negotiation window will be characterised by aggressive testing rather than genuine stabilisation. While the action on the cyber front never ceases, its importance rises concurrently with lulls in kinetic operations. Ultimately, the events in the Persian Gulf illustrate a profound shift in modern conflict: the total obsolescence of a clean binary between “war” and “peace.”
The compromise of critical networks, the doxxing of military personnel, and the targeting of civilian supply chains are not precursors to a future war – they are the permanent backdrop to any politically contested relationship. For global policymakers, defence contractors, and critical infrastructure operators, the lesson of the Hormuz crisis is clear: conventional weapons may occasionally fall silent, but the wires remain hot indefinitely. The tactical successes achieved by Washington have disrupted Tehran’s immediate architecture, but they have also accelerated its retreat into an era of permanent digital and maritime attrition where the battlefield is everywhere, and the conflict never truly ends.
Thus, organisations should treat any reduction in military activity as a period of heightened cyber exposure rather than reduced risk, with particular emphasis on identity security, internet-facing infrastructure, and operational technology resilience.

Iran’s cyber activity is not unified under a single command but operates as a layered ecosystem: IRGC intelligence and cyber-electronic organs, the Ministry of Intelligence and Security (MOIS/VAJA), contractor front companies, and hacktivist or “faketivist” personas coordinated by those services (CISA/FBI joint fact sheet, 30 June 2025). Named APT groups map imperfectly across vendors and are frequently conflated – Handala alone is tracked variously as overlapping Void Manticore, Banished Kitten, and Storm-0842. The table below summarises the actors most relevant to Hormuz-adjacent shipping, energy, and government targets.
| Actor | Assessed Sponsor / Sectorsx | Key TTPs | Notable Incident |
| APT33 / APT35 / APT42 | IRGC-IO; govt, defence, diaspora, dissidents | Spear-phishing, password spraying, cloud/identity abuse (T1566, T1110.003, T1078) | SpearSpecter family-member targeting campaign (Nov 2025) |
| APT34/OilRig, MuddyWater | MOIS/VAJA; Gulf govt, oil & gas, telecom | Edge-device CVEs, web shells, RMM-tool abuse, DNS tunneling (T1190, T1505.003, T1219) | MuddyWater Oct 2025 campaign, 100+ orgs incl. embassies & maritime operators |
| CyberAv3ngers | IRGC-CEC; water, energy, fuel, OT/ICS | Internet-exposed PLC/HMI, default credentials, custom Linux IoT malware | 2026 pivot to CVE-2021-22681 (Rockwell, no patch); AA26-097A updated 22 Jul 2026 |
| Handala Hack | MOIS front; healthcare, defence, govt officials | MDM/credential abuse for mass device wipe, staged leaks (T1072) | Stryker Corp. wipe (200,000+ devices, 11 Mar 2026); Kash Patel email breach |
| Fox Kitten / Pioneer Kitten | Access-brokering; opportunistic, broad sectors | VPN/firewall CVE exploitation, Shodan recon, backdoor accounts (T1190, T1053.005) | Domain-admin access resold to ALPHV/BlackCat, RansomHouse affiliates |
| Predatory Sparrow | Israel-aligned; Iranian banking, crypto, industry | Deep pre-positioning, financial/OT wipers, fund destruction | Bank Sepah wipe + $90M Nobitex burn (17–18 Jun 2025) |
| Hacktivist / faketivist ecosystem | Noise, claim-making; opportunistic | DDoS, defacement, recycled leaks (T1498, T1499, T1491.002) | ~119 aligned groups by Jun 2025; most claims exaggerated or recycled (open-source tracking) |
Named groups map imperfectly across vendors and are frequently conflated. Sponsor attributions reflect assessed linkages; incidents are described as reported in open sources.
State agencies vs. proxies. IRGC-IO and IRGC-CEC pursue distinct missions – long-dwell intelligence collection versus direct OT/ICS disruption – while MOIS/VAJA sponsors the broader espionage and destructive apparatus, including the handoff pattern seen when Scarred Manticore’s stealthy access is passed to Void Manticore for the destructive phase. This division of labour matters operationally: an intrusion that looks like routine espionage can be repurposed for sabotage with little warning.
Hacktivist activity volume is significant – roughly 119 hacktivist groups had aligned to the conflict by June 2025 according to open-source tracking, but independent analysis consistently finds that most of their claims are exaggerated, recycled from old breaches, or fabricated outright – CyberAv3ngers’ own 2023 claim against Israel’s Dorad power station reused imagery from an unrelated leak. The consequential threat remains a small number of state fronts with demonstrated wiper and OT capability, not the DDoS and defacement noise around them. However, CYFIRMA assesses that their statements and actions indicate a willingness by Tehran to use proxies for opportunistic attacks on targets in the GCC, the U.S., Israel, or any country considered friendly to these actors.
The diagram below shows a five-stage escalation ladder – from cyber pre-positioning through OT disruption, grey-zone operations, and economic coercion to kinetic conflict – with the first two stages continuing regardless of ceasefire status.
