Midyear Assessment Finds Iran-Linked Cyber Risk Centered on Persistent Access and Trusted Pathways

Summary
SentinelLABS assesses that Iran-linked cyber activity remains focused on persistent access, espionage, persona-led coercion, and exposed OT systems, while public claims often exceed verified effects and visibility inside Iran remains limited.
Key points
- The assessment identifies persistent access through compromised accounts, service providers, remote-management tools, and trusted administrators as a strategic risk that can enable later collection or disruption.
- Iran-linked activity spans distinct state-linked operators, surveillance clusters, personas, and opportunists; public labels do not necessarily represent separate actors or proven command relationships.
- MOIS-linked personas combine intrusion, data disclosure, destruction, and coercion. Claims about impact, including some associated with the Stryker incident, remain unverified beyond confirmed victim or government reporting.
- A U.S. government advisory documented Iranian-affiliated activity against internet-facing Rockwell Automation and Allen-Bradley PLCs, with reported operational disruption and financial loss. Interface access alone does not prove process manipulation or physical impact.
- Iran's June banking disruptions affected shared services across multiple banks, but public evidence does not establish a single coordinated campaign or identify an actor; the assessment highlights concentration and recovery dependencies.
- The assessment says connectivity restrictions, fragmented disclosure, and surveillance inside Iran limit incident visibility, while informal channels used to bypass restrictions can expose users to malware such as MarkiRAT.
- Defender priorities include securing identity, cloud, RMM, and service-provider access; removing direct OT exposure; strengthening remote access and monitoring; and ensuring recovery systems do not share compromised dependencies.
Article Details
- Publisher
- Sentinel One Labs
- Report Period
- Assessment current as of 2026-07-21; incidents discussed primarily from February through June 2026.
- Scope
- Midyear assessment of Iran-linked cyber activity, cyber-physical risk, incidents inside Iran, and defender priorities.
- Key Statistics
- Unit 42 identified six new Screening Serpens RAT variants deployed between February and April against apparent targets in the United States, Israel, the UAE, and the wider Middle East.
- On June 14, Iranian authorities reported that an attack on shared communications infrastructure disrupted services at four banks.
- A second reported attack on June 23 disrupted card services at three banks.
- The article reports that Iran began restoring international connectivity after an 88-day shutdown; restoration was partial and uneven.
- The U.S. Department of Justice seized four domains associated with Handala, Homeland Justice, KarmaBelow80, and a related Red Wanted operation in March.
- Recommendations
- Review identity, cloud, remote-management, and service-provider relationships for persistent access and trusted pathways; map shared dependencies and recovery paths.
- Coordinate technical response, legal review, communications, and physical-safety support during persona-led incidents, since publication and employee targeting may begin before incident scoping is complete.
- For OT environments, remove direct internet exposure, put remote access behind authenticated gateways with phishing-resistant MFA, restrict programming-mode and logic changes, and limit vendor access by source and time.
- Monitor engineering workstations and industrial protocols, preserve offline project files and known-good configurations, and verify that recovery does not rely on the same potentially compromised identity, virtualization, or management environment.
- Validate claims of cyber-physical impact with evidence such as logs, process data, engineering review, operator testimony, timestamps, configuration evidence, or independent confirmation.
People
Threat Actors
APT34Associated with persistent regional espionage, commonly linked in the article to MOIS; previously documented activity targeted Iraqi government infrastructure.APT42Described as IRGC-IO-linked and engaged in high-trust social engineering and cloud collection; operations targeted journalists, researchers, NGOs, academics, activists, and government-linked individuals.Banished KittenListed as a corresponding label in the article's working crosswalk for Void Manticore; the article cautions that labels are not necessarily one-to-one aliases.Cavern ManticoreDescribed in Check Point reporting as using existing RMM access and compromised IT-provider environments to reach targets; its MOIS relationship is assessed at moderate confidence.CL-STA-1128Unit 42's cluster label, mapped in the article to CyberAv3ngers; the article cautions that this does not attribute every exposed PLC incident to the cluster.CyberAv3ngersDescribed as IRGC-CEC-affiliated and associated with opportunistic OT targeting; government agencies referenced earlier activity associated with the group.Domestic KittenListed as related to TAG-182, explicitly not as an alias; the article describes the activity set as surveillance of dissidents and diaspora.Educated ManticoreListed as a cross-reference for APT42 attributed to Check Point; the article does not assert that all labels are exact aliases.Ferocious KittenListed as related to TAG-182, explicitly not as an alias; the article describes the activity set as surveillance of dissidents and diaspora.Gonjeshke DarandeListed as a label corresponding to Predatory Sparrow; the article describes it as a comparison case and does not attribute the June 2026 banking disruptions to it.GreenEchoListed alongside Domestic Kitten as a related label for TAG-182, not as an alias.Handala Hack TeamMOIS-linked public persona associated with intrusion, destructive claims, data publication, doxxing, and threats; the article treats it as related to other fronts, not as an interchangeable strict alias.Homeland JusticeMOIS-linked public persona associated with destructive, hack-and-leak, and influence operations; the article treats it as related to other fronts, not as an interchangeable strict alias.IRGC Cyber-Electronic CommandNamed as an organization associated with opportunistic OT targeting; the article also references earlier activity associated with CyberAv3ngers.IRGC Intelligence OrganizationNamed as an organization to which Iran-linked cyber operators are tied; APT42 is described as IRGC-IO-linked.KarmaListed as a persona associated with the Void Manticore crosswalk and later described as a related MOIS-linked front.LyceumNamed as having technical and operational overlap with Cavern Manticore in Check Point's assessment.Mango SandstormListed as a corresponding label for the MuddyWater cluster in the article's working crosswalk; labels are not necessarily exact aliases.MOISThe article links operators and persona-led destructive, espionage, and access-enablement activity to MOIS; the ministry is described as one part of Iran's cyber ecosystem.MuddyWaterDescribed as a MOIS-subordinate espionage and access-enablement cluster; Check Point assessed Cavern Manticore had technical and operational overlap with MuddyWater.OilRigListed as a corresponding label for APT34 in the article's working crosswalk; labels are not necessarily exact aliases.Predatory SparrowDescribed as a widely reported Israel-linked actor and comparison case for prior operations against Iranian financial targets; the article explicitly says the June 2026 banking disruptions are not attributed to it.Rampant KittenListed as related to TAG-182, explicitly not as an alias; the article describes the activity set as surveillance of dissidents and diaspora.Red SandstormListed as a corresponding label in the article's working crosswalk for Void Manticore; the article cautions that labels are not necessarily one-to-one aliases.Scarred ManticoreCheck Point documented collaboration involving this named actor and MOIS-linked personas; the article does not claim the personas are interchangeable aliases.Screening SerpensConducted recruitment-themed social-engineering campaigns; Unit 42 identified six new RAT variants deployed between February and April.SeedwormIdentified in the article as a label for the MuddyWater cluster; activity attributed to the cluster included backdoors and an attempted data transfer to commercial cloud storage.Storm-0784Microsoft's label for the cluster Unit 42 maps to CyberAv3ngers; the article says this mapping does not prove every exposed PLC incident involved the same operator.Storm-0842Listed as a corresponding label in the article's working crosswalk for Void Manticore; the article cautions that labels are not necessarily one-to-one aliases.TAG-145Listed as a corresponding label in the article's working crosswalk for Void Manticore; the article cautions that labels are not necessarily one-to-one aliases.TAG-182Associated with surveillance of dissidents and diaspora; recent activity used lures to distribute MarkiRAT to Farsi-speaking users inside and outside Iran. No sponsor was publicly attributed with confidence.Void ManticoreMOIS-linked cluster associated with destructive, hack-and-leak, and influence operations through public personas. The article presents the related labels as a working crosswalk, not necessarily exact aliases.
Malware
Vendors
Microsofton Stryker is the clearest public case for this layer. Stryker confirmed global disruption to its Microsoft environment affecting ordering, manufacturing, and shipping. Early statements said no malware had beenRockwell Automationactivity against U.S. operational technology is the April 7 joint advisory on internet-facing Rockwell Automation and Allen-Bradley PLCs, documenting activity against government facilities, water and wastewater
Products
Allen-Bradley PLCsoperational technology is the April 7 joint advisory on internet-facing Rockwell Automation and Allen-Bradley PLCs, documenting activity against government facilities, water and wastewater organizations, and energyRTKBaseAnalysis of the actor’s published material supported access to customer billing data and an internal RTKBase/NTRIP GPS-correction environment used by field crews. Cal Water said it was investigating and thatSysAidSysAid itself was not compromised, and no SysAid vulnerability was involved. The actor already had access and abused a legitimate deployment feature, and in many intrusions the weakness is the authority already granted
Countries
IranIran-linked activity is not a single threat set. MOIS, the IRGC Intelligence Organization, the IRGC Cyber-Electronic Command, personas, surveillance operators, and opportunists pursue distinct missions.Iraqmission of collecting political, diplomatic, and telecommunications intelligence from neighboring states. Iraq and the Gulf are not peripheral theaters simply because the visible strikes occur elsewhere.IsraelComparison case only: destructive anti-Iran operations, widely reported as Israel-linkedUAEvariants deployed between February and April against apparent targets in the United States, Israel, the UAE, and the wider Middle East. The campaigns continued the actor’s tailored recruitment lures while addingUnited Statesidentified six new RAT variants deployed between February and April against apparent targets in the United States, Israel, the UAE, and the wider Middle East. The campaigns continued the actor’s tailored recruitment
Industries
AviationBankingBanking: The Dependency Is The Strategic FindingDefense and aerospacebank, a U.S. airport, nonprofits, and the Israeli operation of a U.S. software supplier serving defense and aerospace customers. Researchers identified multiple backdoors and an attempted transfer of data toEnergyPLCs, documenting activity against government facilities, water and wastewater organizations, and energy environments, in several cases with operational disruption and financial loss.Nonprofitsearly February, before the opening strikes. Affected environments included a U.S. bank, a U.S. airport, nonprofits, and the Israeli operation of a U.S. software supplier serving defense and aerospace customers.TelecommunicationsIraqi government infrastructure shows a durable mission of collecting political, diplomatic, and telecommunications intelligence from neighboring states. Iraq and the Gulf are not peripheral theaters simply becauseWater and wastewaterRockwell Automation and Allen-Bradley PLCs, documenting activity against government facilities, water and wastewater organizations, and energy environments, in several cases with operational disruption and financial