Cyber Retaliation: Analyzing Iranian Cyber Activity Following Operation Epic Fury

Source: Tenable Blog

Author: Research Special Operations

URL: https://www.tenable.com/blog/cyber-retaliation-analyzing-iranian-cyber-activity-following-operation-epic-fury

ONE SENTENCE SUMMARY:

Post–Operation Epic Fury, Iranian MOIS-linked actors escalated from espionage to disruptive hybrid retaliation, abusing criminal infrastructure and exploiting IP-camera vulnerabilities.

MAIN POINTS:

  1. Retaliatory cyber activity surged alongside continued kinetic strikes against Iranian leadership and infrastructure.
  2. Campaigns shifted toward coordinated disruptive and destructive operations against Western and regional targets.
  3. MOIS-affiliated groups MuddyWater and Handala showed notably increased malicious activity.
  4. MuddyWater pre-positioned access weeks earlier, targeting U.S. and Israeli organizations.
  5. Newly identified backdoors Dindoor and Fakeset were linked to MuddyWater intrusions.
  6. Operation Olalampo targeted MENA entities and used Telegram bot command-and-control.
  7. Handala collaborates with initial-access brokers, then deploys custom wipers after exfiltration.
  8. Handala claimed a destructive attack on Stryker, including Intune-related mobile device wiping.
  9. MOIS-linked actors increasingly use ransomware/criminal infrastructure (e.g., Qilin) to obscure attribution.
  10. Iranian-nexus operators boosted Hikvision/Dahua IP camera exploitation using multiple known CVEs.

TAKEAWAYS:

  1. Expect hybrid retaliation blending cyber disruption with geopolitical and physical-warfare objectives.
  2. Prioritize detection of pre-positioning behavior and handoffs between access brokers and wiper operators.
  3. Treat cybercriminal tooling and infrastructure reuse as an intentional MOIS deniability strategy.
  4. Patch and monitor internet-connected cameras and management platforms, especially Hikvision/Dahua.
  5. Increase preparedness across aviation, finance, healthcare, telecom, and critical infrastructure sectors.