The invisible war: Iran’s evolving cyberattacks bring battlefront to small-town America


The invisible war: Iran's evolving cyberattacks bring battlefront to small-town America
A war that began with airstrikes over Iran is now being felt in places far from the Middle East.

On February 28, the US and Israel unleashed Operation Roaring Lion. Dramatic footage of missiles striking military, nuclear and government targets across Iran was broadcast around the world.But as the physical assault unfolded, another battle raged in parallel — one with no fighter jets in the sky and no missiles streaking across the horizon.Coordinated cyberattacks tore through Iran’s networks, compromising news platforms and a popular prayer app, disrupting communications and replacing state television broadcasts with messages from Donald Trump and Benjamin Netanyahu.The physical assault was visible to the world; the digital blitzkrieg was largely invisible.It was a glimpse of a new kind of warfare. And Iran fought back.Iranian cyberoperators and affiliated groups targeted US and Israeli systems, stole sensitive information and disrupted infrastructure, increasingly extending the conflict far beyond the Middle East.The latest warning came in July, when cyberattacks hit water and wastewater facilities across at least 12 US states, including more than 30 systems in Minnesota.US authorities have not conclusively attributed the attacks to Tehran, but Iranian-linked actors are among the suspects.CyberAv3ngers, which is affiliated with the Islamic Revolutionary Guard Corps (IRGC), issued a release regarding cyberattacks; while APT IRAN, which is linked to CyberAv3ngers, declared in an August 11 statement on its Telegram channel: “The attack on Minnesota was the work of the CyberAv3ngers and us, and we take direct responsibility for it.”

We have carried out attacks on US infra, and we warn America to back down … threatening Iran’s infra and shedding the blood of Iran’s children has a very heavy price … our intention in attacking Minnesota was only to warn … US electricity, telecommunications, water is under our control, and whenever America acts arrogantly, we will press the button

CyberAv3ngers and APT IRAN

What began as a shadowy adjunct to conventional warfare is now a battlefield in its own right — one where the target may not be a military base, but the network controlling a water pump in small-town America.The physical war may be thousands of kilometres away. The cyberwar is already knocking on America’s door.

The invisible war

Within the first hours of the 2026 US-Israeli strikes, multiple pro-regime Iranian news agencies were simultaneously compromised.Legitimate-looking but fabricated content was injected into their front pages, designed to degrade morale of pro-regime forces using classic PSYOPS tactics. The sites were quickly taken down and restored, but not before reaching a wide audience during the most critical early hours. By injecting content at the exact moment Iranians turned to state media for strike coverage, the attackers maximised psychological impact during the regime’s most vulnerable window.

US-Israel-Iran cyber war

The physical assault was visible to the world; the digital blitzkrieg was largely invisible.

The simultaneous compromise of multiple outlets suggests pre-positioned access – these intrusions were prepared well in advance and activated on cue.Shortly after, BadeSabaa, a popular Iranian prayer time app with over 30 million installations from the Iranian app store, was hijacked.Push notifications were sent to its entire user base, calling on army members to surrender and join the people if they wanted to survive.The target selection was precise. As a prayer time app, its users skew heavily religious and conservative, a demographic overlapping significantly with pro-regime supporters and military personnel.During the second day of strikes, Iranian national television’s Channel 3 satellite streams on IntelSat were hijacked. Viewers were shown video broadcasts of speeches by Trump and Netanyahu instead of regular programming.In repsonse, Iran went into full internet blackout, not only as a reaction to the cyberattacks but to stifle any dissent, and control information reaching the public.

Iran retaliates

In the 6 months preceding the 2026 US-Iran war, the global distribution of cyberattacks reflected expected threat trends: the US led with 18% of all incidents, followed by India (6%), Israel (6%), Indonesia (5%), and Thailand (5%).But in the 24 hours following the February 28 strikes, the picture shifted dramatically.

Iran cyberwar

Attacks on Israel spiked within 24 hours after the Iran war began.

Israel jumped from 6% to 21% of global incidents – a 3.5x increase. Crucially, Gulf states such as UAE, Kuwait, and Saudi Arabia appeared in the top 5 for the first time, reflecting retaliatory and spillover targeting linked to their proximity to the conflict and hosting of US military assets.Analysis of 179 threat incidents painted a clear picture of the hacktivist playbook.Denial-of-service (DDoS) attacks dominated at 37% of all incidents, consistent with hacktivist preference for high-visibility, low-effort disruption.But the data also revealed more concerning activities: 9 incidents involved compromise of security cameras and industrial control systems used to operate machinery and infrastructure in the US; alleged breaches of Israeli Defense Forces servers and Ministry of Defence data, and targeted data leaks of military personnel and civilian information.Iran had been preparing.

A decade of cyber escalation

The invisible war did not start in 2026.The roots trace back to Stuxnet (2010), the US-Israeli cyberweapon that infiltrated industrial systems associated with Iran’s nuclear programme and physically destroyed centrifuges at Natanz. The US also planned an effort known as Nitro Zeus, a programme to disrupt Iranian air defences, communications and power grid.Iran could not match the US aircraft for aircraft, missile for missile or carrier for carrier. But it could target the networks that connected financial institutions, telecommunications systems, industrial facilities and government agencies.The Iranian response evolved rapidly.In 2012, Iranian-linked actors were blamed for Operation Ababil, a campaign of distributed denial-of-service attacks against US banks. The attacks temporarily disrupted online banking services and demonstrated that Iran did not need to destroy a bank’s physical infrastructure to impose costs on it.The same period saw the Shamoon attack against Saudi Aramco, in which data on thousands of computers was erased. US officials attributed the attack to Iran and launched counter cyberoperations.Between 2013 and 2017, Iran-based Mabna Institute targeted computer systems of 144 American universities and 42 private sector firms. The group may have stolen over 31 terabytes of academic data and intellectual property worth approximately $3.4bn, said the US Department of Justice.Over time, Tehran developed a broader ecosystem involving government organisations, military-linked cyber units, contractors and proxy groups.During the June 2025 12-Day War, cyberattacks surged 700% within 48 hours.Pro-Israel cybersabotage group Predatory Sparrow wiped data of Iran’s state-owned Bank Sepah; and burned $90 million in Nobitex cryptocurrency.Over 100 pro-Iranian hacktivist groups mobilised on Telegram. Israel was the most targeted country by geopolitically motivated hackers in 2025, absorbing 12.2% of all global attacks.By February 2026, Iran was primed to use cyberwarfare to its asymmetric advantage.

Iran’s strike on Stryker

On March 11, US company Stryker suffered a major cyberattack that disrupted its global Microsoft environment.The Iran-linked Handala hacking group claimed responsibility and portrayed the operation as retaliation for the US-Israeli military campaign.Stryker confirmed that it had suffered a cyberattack and was experiencing a global network disruption. The attackers claimed they had wiped more than 200,000 systems and extracted 50 terabytes of data.The attack represented a major escalation because of what Stryker does.It is not a weapons manufacturer. It makes medical devices used by US hospitals.That makes the target strategically interesting. An attacker does not necessarily need to strike a hospital directly. Disrupting a company that supplies the healthcare system can create pressure further downstream.This is what makes modern cyberwarfare so difficult to contain.The target may be civilian. The consequences may be civilian. And the attacker can still regard the operation as part of a military campaign.

US water system under cyberseige

Following the attack, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency and Environmental Protection Agency warned that Iranian-affiliated actors were exploiting programmable logic controllers (PLCs) across American critical infrastructure.PLCs are not glamorous pieces of technology. They are industrial computers that control physical processes: pumps, valves, motors, pressure systems and other machinery.That is precisely why they matter.Compromising a PLC means crossing the line from stealing data to potentially manipulating the physical world.The April advisory said Iranian-affiliated actors had already caused operational disruptions and financial losses, including configuration wiping, manipulation of mechanical sensors and disruption of human-machine interfaces.

US-Israel-Iran cyber war

More than 30 community water systems were targeted on July 26 and 27.

Then came the Minnesota incidents.Over 30 community water systems were targeted on July 26 and 27. Investigators have not publicly established Iranian responsibility, but the attacks resembled previous Iranian-linked intrusions into US water infrastructure.The attack expanded and eventually covered systems across at least 12 states.Some systems lost remote control, experienced pressure problems or had to revert to manual operations.

Cyberattacks on US

At least 100 facilities across the US have been targeted

The New York Times reported that at least 100 facilities across the US have been targeted, though the names and locations of these facilities were not released.The attacks were not catastrophic. But that is precisely what makes them significant.A missile strike announces itself. A cyberattack can be almost invisible until a pump stops working, a hospital’s systems go offline, a company’s computers are wiped or a mobile phone quietly reveals the location of a soldier.

The SS7 exploit: From opportunistic hacking to wartime strategy

Perhaps the most striking development is that Iran’s cyber campaign is no longer limited to hacking computers.It is increasingly about exploiting the digital ecosystem around people.In July, reporting based on telecom data indicated that Iranian actors had exploited weaknesses in SS7, an old signalling protocol used by mobile networks, to track the locations of US military personnel and contractors in the Middle East.

US-Israel-Iran cyber war

SS7 is a signalling protocol used by mobile networks.

SS7 vulnerabilities have long been known. They can allow sophisticated actors to obtain information about where a mobile device is located.In this case, the reporting indicated that Iranian actors used telecom infrastructure and commercial advertising technology to locate US personnel in countries including Iraq and Bahrain. The information may have assisted subsequent attacks on US personnel, though the precise operational links remain difficult to establish.

US-Israel-Iran cyber war

Iranian actors used telecom infra to locate US personnel in the Gulf.

The implication is profound.A smartphone does not need to be hacked for it to become an intelligence source.The networks around it can be enough.The same is true of cameras, advertising platforms, cloud services, internet-connected industrial equipment and corporate identity systems.

Information warfare

Iran’s cyber strategy is rooted in a broader doctrine of asymmetric warfare. Faced with conventionally superior US and Israeli military capabilities, Tehran has sought ways to impose costs without necessarily confronting those forces symmetrically.Cyber capabilities fit that strategy particularly well.Iranian actors have targeted local government systems, gas-station payment infrastructure and water facilities in the US. Pro-Iranian hacktivist groups have simultaneously targeted organisations across the Middle East. US and Israeli officials, military personnel and intelligence-linked individuals have also faced hack-and-leak operations.At first glance, these attacks can appear disconnected. A compromised government system, leaked personal information or disrupted infrastructure may seem to have little direct bearing on a war thousands of kilometres away.But their value can be measured in psychological and political terms.

US-Israel-Iran cyber war

Iran’s cyber strategy is rooted in a broader doctrine of asymmetric warfare.

The objective is partly to demonstrate reach. If Iranian-linked operators can penetrate systems belonging to senior officials, military personnel or critical infrastructure, they can undermine the perception that those institutions are secure. That can have an effect disproportionate to the technical damage caused.The second objective is friction. Repeated cyber incidents can create uncertainty among businesses, governments and ordinary citizens. They generate a persistent sense that the conflict can reach into everyday life, even when no missiles are falling.This is where cyber operations become information warfare. Their physical effect may be limited, but their psychological effect can be amplified by social media, news coverage and public anxiety. Iran can therefore impose costs at a distance while attempting to shape how the conflict is perceived by domestic and international audiences.

AI is making the cyber campaign faster and larger

Artificial intelligence is adding another layer to this strategy.Recent threat-intelligence reporting indicates that Iranian actors have used AI across multiple stages of cyber and information operations, including reconnaissance, code and malware development, social engineering, and the creation and manipulation of content.AI has therefore not fundamentally altered Iran’s strategic logic, but it has increased the speed, scale, reach and potential impact of its operations.

The threat actors are conducting reconnaissance and capability development against PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools

CISA advisory

AI does not necessarily give Iran a revolutionary new weapon. Instead, it can make existing techniques more efficient. Reconnaissance can be accelerated, convincing social-engineering material can be produced at greater scale, and cyber operators can potentially develop or modify malicious code more quickly.For countries defending critical infrastructure, this means that the problem is not merely the sophistication of individual attacks. It is the possibility of a sustained volume of activity that continually tests weak points.

The big picture

A war that began with missiles and airstrikes over Iran is increasingly being felt in places far removed from the Middle Eastern battlefield.And unlike a missile, the weapon may not arrive with a warning.What began largely as opportunistic disruption, espionage and hacktivist activity has increasingly become an integrated component of Iran’s broader war strategy, used not only to steal information or disrupt systems, but to support kinetic operations, influence perceptions and impose costs on adversaries far beyond the battlefield.Cyber operations thus function as an enabling layer across Iran’s asymmetric strategy.The Strait of Hormuz and Iran’s ability to disrupt energy flows remain much more powerful sources of leverage. Missiles, drones and economic pressure can produce more immediate physical effects. But cyber capabilities allow Tehran to extend that pressure into domains that are geographically distant and politically sensitive.For the United States, the challenge will be particularly acute as the conflict continues and the 2026 midterm elections approach. Iran has a history of targeting US elections and political campaigns, making cyber resilience increasingly important not only for critical infrastructure but also for the political system.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *