{"id":15015,"date":"2026-08-21T14:21:46","date_gmt":"2026-08-21T14:21:46","guid":{"rendered":"https:\/\/koshalsambada.in\/?p=15015"},"modified":"2026-08-21T14:21:46","modified_gmt":"2026-08-21T14:21:46","slug":"the-invisible-war-irans-evolving-cyberattacks-bring-battlefront-to-small-town-america","status":"publish","type":"post","link":"https:\/\/koshalsambada.in\/?p=15015","title":{"rendered":"The invisible war: Iran&#8217;s evolving cyberattacks bring battlefront to small-town America"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-133292129,imgsize-139118,width-400,height-225,resizemode-4\/us-israel-iran-cyber-war.jpg\" alt=\"The invisible war: Iran's evolving cyberattacks bring battlefront to small-town America\" title=\"A war that began with airstrikes over Iran is now being felt in places far from the Middle East.\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<div class=\"Ta7d_ img_cptn\"><span title=\"A war that began with airstrikes over Iran is now being felt in places far from the Middle East.\">A war that began with airstrikes over Iran is now being felt in places far from the Middle East.<\/span><\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>On February 28, the US and Israel unleashed Operation Roaring Lion. Dramatic footage of missiles striking military, nuclear and government targets across Iran was broadcast around the world.<span class=\"id-r-component br\" data-pos=\"2\"\/>But as the physical assault unfolded, another battle raged in parallel \u2014 one with no fighter jets in the sky and no missiles streaking across the horizon.<span class=\"id-r-component br\" data-pos=\"4\"\/>Coordinated cyberattacks tore through Iran\u2019s networks, compromising news platforms and a popular prayer app, disrupting communications and replacing state television broadcasts with messages from <a href=\"https:\/\/timesofindia.indiatimes.com\/topic\/donald-trump\" styleobj=\"[object Object]\" class=\"\" commonstate=\"[object Object]\" frmappuse=\"1\" target=\"_blank\" rel=\"noopener\">Donald Trump<\/a> and Benjamin <a href=\"https:\/\/timesofindia.indiatimes.com\/topic\/netanyahu\" styleobj=\"[object Object]\" class=\"\" commonstate=\"[object Object]\" frmappuse=\"1\" target=\"_blank\" rel=\"noopener\">Netanyahu<\/a>.<span class=\"id-r-component br\" data-pos=\"10\"\/>The physical assault was visible to the world; the digital blitzkrieg was largely invisible.<span class=\"id-r-component br\" data-pos=\"14\"\/>It was a glimpse of a new kind of warfare. And Iran fought back.<span class=\"id-r-component br\" data-pos=\"16\"\/>Iranian cyberoperators and affiliated groups targeted US and Israeli systems, stole sensitive information and disrupted infrastructure, increasingly extending the conflict far beyond the Middle East.<span class=\"id-r-component br\" data-pos=\"18\"\/>The latest warning came in July, when cyberattacks hit water and wastewater facilities across at least 12 US states, including more than 30 systems in Minnesota.<span class=\"id-r-component br\" data-pos=\"21\"\/>US authorities have not conclusively attributed the attacks to Tehran, but Iranian-linked actors are among the suspects.<span class=\"id-r-component br\" data-pos=\"23\"\/>CyberAv3ngers, which is affiliated with the Islamic Revolutionary Guard Corps (IRGC), issued a release regarding cyberattacks; while APT IRAN, which is linked to CyberAv3ngers, declared in an August 11 statement on its Telegram channel: &#8220;The attack on Minnesota was the work of the CyberAv3ngers and us, and we take direct responsibility for it.&#8221;<span class=\"id-r-component br\" data-pos=\"26\"\/><\/p>\n<div class=\"MNrkd   \">\n<p>We have carried out attacks on US infra, and we warn America to back down &#8230; threatening Iran\u2019s infra and shedding the blood of Iran&#8217;s children has a very heavy price &#8230; our intention in attacking Minnesota was only to warn &#8230; US electricity, telecommunications, water is under our control, and whenever America acts arrogantly, we will press the button<\/p>\n<p>CyberAv3ngers and APT IRAN<small\/><\/p>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"28\"\/>What began as a shadowy adjunct to conventional warfare is now a battlefield in its own right \u2014 one where the target may not be a military base, but the network controlling a water pump in small-town America.<span class=\"id-r-component br\" data-pos=\"30\"\/>The physical war may be thousands of kilometres away. The cyberwar is already knocking on America\u2019s door.<span class=\"id-r-component br\" data-pos=\"32\"\/><\/p>\n<p><h2>The <keyword id=\"38534334\" type=\"General\" weightage=\"20\" keywordseo=\"invisible-war\" source=\"Orion\">invisible war<\/keyword><\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"34\"\/>Within the first hours of the 2026 US-Israeli strikes, multiple pro-regime Iranian news agencies were simultaneously compromised.<span class=\"id-r-component br\" data-pos=\"37\"\/>Legitimate-looking but fabricated content was injected into their front pages, designed to degrade morale of pro-regime forces using classic PSYOPS tactics. The sites were quickly taken down and restored, but not before reaching a wide audience during the most critical early hours. By injecting content at the exact moment Iranians turned to state media for strike coverage, the attackers maximised psychological impact during the regime&#8217;s most vulnerable window.<span class=\"id-r-component br\" data-pos=\"40\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"US-Israel-Iran cyber war\" msid=\"133291665\" imgsize=\"448056\" resizemode=\"4\" width=\"\" title=\" The physical assault was visible to the world; the digital blitzkrieg was largely invisible.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-448056,msid-133291665\/us-israel-iran-cyber-war.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p> The physical assault was visible to the world; the digital blitzkrieg was largely invisible.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"42\"\/>The simultaneous compromise of multiple outlets suggests pre-positioned access \u2013 these intrusions were prepared well in advance and activated on cue.<span class=\"id-r-component br\" data-pos=\"44\"\/>Shortly after, BadeSabaa, a popular Iranian prayer time app with over 30 million installations from the Iranian app store, was hijacked.<span class=\"id-r-component br\" data-pos=\"46\"\/>Push notifications were sent to its entire user base, calling on army members to surrender and join the people if they wanted to survive.<span class=\"id-r-component br\" data-pos=\"49\"\/>The target selection was precise. As a prayer time app, its users skew heavily religious and conservative, a demographic overlapping significantly with pro-regime supporters and military personnel.<span class=\"id-r-component br\" data-pos=\"51\"\/>During the second day of strikes, Iranian national television&#8217;s Channel 3 satellite streams on IntelSat were hijacked. Viewers were shown video broadcasts of speeches by Trump and Netanyahu instead of regular programming.<span class=\"id-r-component br\" data-pos=\"54\"\/>In repsonse, Iran went into full internet blackout, not only as a reaction to the cyberattacks but to stifle any dissent, and control information reaching the public.<span class=\"id-r-component br\" data-pos=\"56\"\/><\/p>\n<p><h3>Iran retaliates<\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"58\"\/>In the 6 months preceding the 2026 US-Iran war, the global distribution of cyberattacks reflected expected threat trends: the US led with 18% of all incidents, followed by India (6%), Israel (6%), Indonesia (5%), and Thailand (5%).<span class=\"id-r-component br\" data-pos=\"60\"\/>But in the 24 hours following the February 28 strikes, the picture shifted dramatically.<span class=\"id-r-component br\" data-pos=\"63\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"Iran cyberwar\" msid=\"133277956\" imgsize=\"43920\" resizemode=\"4\" width=\"\" title=\"Attacks on Israel spiked within 24 hours after the Iran war began. \" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-43920,msid-133277956\/iran-cyberwar.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>Attacks on Israel spiked within 24 hours after the Iran war began. <\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"65\"\/>Israel jumped from 6% to 21% of global incidents \u2013 a 3.5x increase. Crucially, Gulf states such as UAE, Kuwait, and Saudi Arabia appeared in the top 5 for the first time, reflecting retaliatory and spillover targeting linked to their proximity to the conflict and hosting of US military assets.<span class=\"id-r-component br\" data-pos=\"67\"\/>Analysis of 179 threat incidents painted a clear picture of the hacktivist playbook.<span class=\"id-r-component br\" data-pos=\"69\"\/>Denial-of-service (DDoS) attacks dominated at 37% of all incidents, consistent with hacktivist preference for high-visibility, low-effort disruption.<span class=\"id-r-component br\" data-pos=\"72\"\/>But the data also revealed more concerning activities: 9 incidents involved compromise of security cameras and industrial control systems used to operate machinery and infrastructure in the US; alleged breaches of Israeli Defense Forces servers and Ministry of Defence data, and targeted data leaks of military personnel and civilian information.<span class=\"id-r-component br\" data-pos=\"74\"\/>Iran had been preparing.<span class=\"id-r-component br\" data-pos=\"76\"\/><\/p>\n<p><h2>A decade of cyber escalation<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"78\"\/>The invisible war did not start in 2026.<span class=\"id-r-component br\" data-pos=\"81\"\/>The roots trace back to Stuxnet (2010), the US-Israeli cyberweapon that infiltrated industrial systems associated with Iran&#8217;s nuclear programme and physically destroyed centrifuges at Natanz. The US also planned an effort known as Nitro Zeus, a programme to disrupt Iranian air defences, communications and power grid.<span class=\"id-r-component br\" data-pos=\"83\"\/>Iran could not match the US aircraft for aircraft, missile for missile or carrier for carrier. <!-- -->But it could target the networks that connected financial institutions, telecommunications systems, industrial facilities and government agencies.<span class=\"id-r-component br\" data-pos=\"87\"\/>The Iranian response evolved rapidly.<span class=\"id-r-component br\" data-pos=\"89\"\/>In 2012, Iranian-linked actors were blamed for Operation Ababil, a campaign of distributed denial-of-service attacks against US banks. The attacks temporarily disrupted online banking services and demonstrated that Iran did not need to destroy a bank&#8217;s physical infrastructure to impose costs on it.<span class=\"id-r-component br\" data-pos=\"92\"\/>The same period saw the Shamoon attack against Saudi Aramco, in which data on thousands of computers was erased. US officials attributed the attack to Iran and launched counter cyberoperations.<span class=\"id-r-component br\" data-pos=\"94\"\/>Between 2013 and 2017, Iran-based <a href=\"https:\/\/timesofindia.indiatimes.com\/world\/us\/us-charges-17-iranians-over-hacking-campaign-targeting-144-universities-firms\/articleshow\/133346777.cms\" styleobj=\"[object Object]\" class=\"\" commonstate=\"[object Object]\" frmappuse=\"1\" target=\"_blank\" rel=\"noopener\">Mabna Institute targeted computer systems of 144 American universities<\/a> and 42 private sector firms. The group may have stolen over 31 terabytes of academic data and intellectual property worth approximately $3.4bn, said the US Department of Justice.<span class=\"id-r-component br\" data-pos=\"98\"\/>Over time, Tehran developed a broader ecosystem involving government organisations, military-linked cyber units, contractors and proxy groups.<span class=\"id-r-component br\" data-pos=\"101\"\/>During the June 2025 12-Day War, cyberattacks surged 700% within 48 hours.<span class=\"id-r-component br\" data-pos=\"103\"\/>Pro-Israel cybersabotage group Predatory Sparrow wiped data of Iran&#8217;s state-owned Bank Sepah; and burned $90 million in Nobitex cryptocurrency.<span class=\"id-r-component br\" data-pos=\"105\"\/>Over 100 pro-Iranian hacktivist groups mobilised on Telegram. Israel was the most targeted country by geopolitically motivated hackers in 2025, absorbing 12.2% of all global attacks.<span class=\"id-r-component br\" data-pos=\"107\"\/>By February 2026, Iran was primed to use cyberwarfare to its asymmetric advantage.<span class=\"id-r-component br\" data-pos=\"110\"\/><\/p>\n<p><h2>Iran&#8217;s strike on Stryker<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"112\"\/>On March 11, US company Stryker suffered a major cyberattack that disrupted its global Microsoft environment.<span class=\"id-r-component br\" data-pos=\"114\"\/>The Iran-linked Handala hacking group claimed responsibility and portrayed the operation as retaliation for the US-Israeli military campaign.<span class=\"id-r-component br\" data-pos=\"116\"\/>Stryker confirmed that it had suffered a cyberattack and was experiencing a global network disruption. The attackers claimed they had wiped more than 200,000 systems and extracted 50 terabytes of data.<span class=\"id-r-component br\" data-pos=\"119\"\/>The attack represented a major escalation because of what Stryker does.<span class=\"id-r-component br\" data-pos=\"121\"\/>It is not a weapons manufacturer. It makes medical devices used by US hospitals.<span class=\"id-r-component br\" data-pos=\"123\"\/>That makes the target strategically interesting. An attacker does not necessarily need to strike a hospital directly. Disrupting a company that supplies the healthcare system can create pressure further downstream.<span class=\"id-r-component br\" data-pos=\"125\"\/>This is what makes modern cyberwarfare so difficult to contain.<span class=\"id-r-component br\" data-pos=\"128\"\/>The target may be civilian. The consequences may be civilian. And the attacker can still regard the operation as part of a military campaign.<span class=\"id-r-component br\" data-pos=\"130\"\/><\/p>\n<p><h2>US water system under cyberseige<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"132\"\/>Following the attack, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency and Environmental Protection Agency <a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/fbi-nsa-and-cisa-issue-urgent-warning-iranian-hackers-hit-critical-us-infrastructure-and-safety-systems\/articleshow\/132595403.cms\" styleobj=\"[object Object]\" class=\"\" commonstate=\"[object Object]\" frmappuse=\"1\" target=\"_blank\" rel=\"noopener\">warned that Iranian-affiliated actors were exploiting<\/a> programmable logic controllers (PLCs) across American critical infrastructure.<span class=\"id-r-component br\" data-pos=\"136\"\/>PLCs are not glamorous pieces of technology. They are industrial computers that control physical processes: pumps, valves, motors, pressure systems and other machinery.<span class=\"id-r-component br\" data-pos=\"139\"\/>That is precisely why they matter.<span class=\"id-r-component br\" data-pos=\"141\"\/>Compromising a PLC means crossing the line from stealing data to potentially manipulating the physical world.<span class=\"id-r-component br\" data-pos=\"143\"\/>The April advisory said Iranian-affiliated actors had already caused operational disruptions and financial losses, including configuration wiping, manipulation of mechanical sensors and disruption of human-machine interfaces.<span class=\"id-r-component br\" data-pos=\"145\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"US-Israel-Iran cyber war\" msid=\"133291830\" imgsize=\"387375\" resizemode=\"4\" width=\"\" title=\" More than 30 community water systems were targeted on July 26 and 27.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-387375,msid-133291830\/us-israel-iran-cyber-war.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p> More than 30 community water systems were targeted on July 26 and 27.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"147\"\/>Then came the Minnesota incidents.<span class=\"id-r-component br\" data-pos=\"150\"\/>Over 30 community water systems were targeted on July 26 and 27. Investigators have not publicly established Iranian responsibility, but the attacks resembled previous Iranian-linked intrusions into US water infrastructure.<span class=\"id-r-component br\" data-pos=\"152\"\/>The attack expanded and eventually covered systems across at least 12 states.<span class=\"id-r-component br\" data-pos=\"154\"\/>Some systems lost remote control, experienced pressure problems or had to revert to manual operations.<span class=\"id-r-component br\" data-pos=\"156\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"Cyberattacks on US\" msid=\"133343246\" imgsize=\"26724\" resizemode=\"4\" width=\"\" title=\" At least 100 facilities across the US\u00a0have been targeted\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-26724,msid-133343246\/cyberattacks-on-us.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p> At least 100 facilities across the US\u00a0have been targeted<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"158\"\/>The New York Times reported that at least 100 facilities across the US have been targeted, though the names and locations of these facilities were not released.<span class=\"id-r-component br\" data-pos=\"161\"\/>The attacks were not catastrophic. But that is precisely what makes them significant.<span class=\"id-r-component br\" data-pos=\"163\"\/>A missile strike announces itself. A cyberattack can be almost invisible until a pump stops working, a hospital&#8217;s systems go offline, a company&#8217;s computers are wiped or a mobile phone quietly reveals the location of a soldier.<span class=\"id-r-component br\" data-pos=\"165\"\/><\/p>\n<p><h2>The SS7 exploit: From opportunistic hacking to wartime strategy<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"167\"\/>Perhaps the most striking development is that Iran&#8217;s cyber campaign is no longer limited to hacking computers.<span class=\"id-r-component br\" data-pos=\"170\"\/>It is increasingly about exploiting the digital ecosystem around people.<span class=\"id-r-component br\" data-pos=\"172\"\/>In July, reporting based on telecom data indicated that Iranian actors had exploited weaknesses in SS7, an old signalling protocol used by mobile networks, to track the locations of US military personnel and contractors in the Middle East.<span class=\"id-r-component br\" data-pos=\"174\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"US-Israel-Iran cyber war\" msid=\"133291853\" imgsize=\"303466\" resizemode=\"4\" width=\"\" title=\" SS7 is a signalling protocol used by mobile networks.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-303466,msid-133291853\/us-israel-iran-cyber-war.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p> SS7 is a signalling protocol used by mobile networks.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"176\"\/>SS7 vulnerabilities have long been known. They can allow sophisticated actors to obtain information about where a mobile device is located.<span class=\"id-r-component br\" data-pos=\"179\"\/>In this case, the reporting indicated that Iranian actors used telecom infrastructure and commercial advertising technology to locate US personnel in countries including Iraq and Bahrain. The information may have assisted subsequent attacks on US personnel, though the precise operational links remain difficult to establish.<span class=\"id-r-component br\" data-pos=\"181\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"US-Israel-Iran cyber war\" msid=\"133291878\" imgsize=\"435267\" resizemode=\"4\" width=\"\" title=\" Iranian actors used telecom infra to locate US personnel in the Gulf.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-435267,msid-133291878\/us-israel-iran-cyber-war.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p> Iranian actors used telecom infra to locate US personnel in the Gulf.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"183\"\/>The implication is profound.<span class=\"id-r-component br\" data-pos=\"185\"\/>A smartphone does not need to be hacked for it to become an intelligence source.<span class=\"id-r-component br\" data-pos=\"188\"\/>The networks around it can be enough.<span class=\"id-r-component br\" data-pos=\"190\"\/>The same is true of cameras, advertising platforms, cloud services, internet-connected industrial equipment and corporate identity systems.<span class=\"id-r-component br\" data-pos=\"192\"\/><\/p>\n<p><h2>Information warfare<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"194\"\/>Iran&#8217;s cyber strategy is rooted in a broader doctrine of asymmetric warfare. Faced with conventionally superior US and Israeli military capabilities, Tehran has sought ways to impose costs without necessarily confronting those forces symmetrically.<span class=\"id-r-component br\" data-pos=\"197\"\/>Cyber capabilities fit that strategy particularly well.<span class=\"id-r-component br\" data-pos=\"199\"\/>Iranian actors have targeted local government systems, gas-station payment infrastructure and water facilities in the US. Pro-Iranian hacktivist groups have simultaneously targeted organisations across the Middle East. US and Israeli officials, military personnel and intelligence-linked individuals have also faced hack-and-leak operations.<span class=\"id-r-component br\" data-pos=\"202\"\/>At first glance, these attacks can appear disconnected. A compromised government system, leaked personal information or disrupted infrastructure may seem to have little direct bearing on a war thousands of kilometres away.<span class=\"id-r-component br\" data-pos=\"204\"\/>But their value can be measured in psychological and political terms.<span class=\"id-r-component br\" data-pos=\"206\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"US-Israel-Iran cyber war\" msid=\"133291967\" imgsize=\"650198\" resizemode=\"4\" width=\"\" title=\" Iran's cyber strategy is rooted in a broader doctrine of asymmetric warfare.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-650198,msid-133291967\/us-israel-iran-cyber-war.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p> Iran&#8217;s cyber strategy is rooted in a broader doctrine of asymmetric warfare.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"208\"\/>The objective is partly to demonstrate reach. If Iranian-linked operators can penetrate systems belonging to senior officials, military personnel or critical infrastructure, they can undermine the perception that those institutions are secure. <!-- -->That can have an effect disproportionate to the technical damage caused.<span class=\"id-r-component br\" data-pos=\"212\"\/>The second objective is friction. Repeated cyber incidents can create uncertainty among businesses, governments and ordinary citizens. They generate a persistent sense that the conflict can reach into everyday life, even when no missiles are falling.<span class=\"id-r-component br\" data-pos=\"214\"\/>This is where cyber operations become information warfare. Their physical effect may be limited, but their psychological effect can be amplified by social media, news coverage and public anxiety. <!-- -->Iran can therefore impose costs at a distance while attempting to shape how the conflict is perceived by domestic and international audiences.<span class=\"id-r-component br\" data-pos=\"218\"\/><\/p>\n<p><h2>AI is making the cyber campaign faster and larger<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"220\"\/>Artificial intelligence is adding another layer to this strategy.<span class=\"id-r-component br\" data-pos=\"222\"\/>Recent threat-intelligence reporting indicates that Iranian actors have used AI across multiple stages of cyber and information operations, including reconnaissance, code and malware development, social engineering, and the creation and manipulation of content.<span class=\"id-r-component br\" data-pos=\"225\"\/>AI has therefore not fundamentally altered Iran&#8217;s strategic logic, but it has increased the speed, scale, reach and potential impact of its operations.<span class=\"id-r-component br\" data-pos=\"227\"\/><\/p>\n<div class=\"MNrkd   \">\n<p>The threat actors are conducting reconnaissance and capability development against PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools<\/p>\n<p>CISA advisory<small\/><\/p>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"229\"\/>AI does not necessarily give Iran a revolutionary new weapon. Instead, it can make existing techniques more efficient. Reconnaissance can be accelerated, convincing social-engineering material can be produced at greater scale, and cyber operators can potentially develop or modify malicious code more quickly.<span class=\"id-r-component br\" data-pos=\"232\"\/>For countries defending critical infrastructure, this means that the problem is not merely the sophistication of individual attacks. It is the possibility of a sustained volume of activity that continually tests weak points.<span class=\"id-r-component br\" data-pos=\"234\"\/><\/p>\n<p><h2>The big picture<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"236\"\/>A war that began with missiles and airstrikes over Iran is increasingly being felt in places far removed from the Middle Eastern battlefield.<span class=\"id-r-component br\" data-pos=\"238\"\/>And unlike a missile, the weapon may not arrive with a warning.<span class=\"id-r-component br\" data-pos=\"241\"\/>What began largely as opportunistic disruption, espionage and hacktivist activity has increasingly become an integrated component of Iran\u2019s broader war strategy, used not only to steal information or disrupt systems, but to support kinetic operations, influence perceptions and impose costs on adversaries far beyond the battlefield.<span class=\"id-r-component br\" data-pos=\"244\"\/>Cyber operations thus function as an enabling layer across Iran&#8217;s asymmetric strategy.<span class=\"id-r-component br\" data-pos=\"247\"\/>The Strait of Hormuz and Iran&#8217;s ability to disrupt energy flows remain much more powerful sources of leverage. Missiles, drones and economic pressure can produce more immediate physical effects. But cyber capabilities allow Tehran to extend that pressure into domains that are geographically distant and politically sensitive.<span class=\"id-r-component br\" data-pos=\"249\"\/>For the United States, the challenge will be particularly acute as the conflict continues and the 2026 midterm elections approach. Iran has a history of targeting US elections and political campaigns, making cyber resilience increasingly important not only for critical infrastructure but also for the political system.<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/world\/middle-east\/the-invisible-war-irans-evolving-cyberattacks-bring-battlefront-to-small-town-america\/articleshow\/133267088.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A war that began with airstrikes over Iran is now being felt in places far from the Middle East. On February 28, the US and Israel unleashed Operation Roaring Lion. Dramatic footage of missiles striking military, nuclear and government targets across Iran was broadcast around the world.But as the physical assault unfolded, another battle raged [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15016,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-15015","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-31"],"magazineBlocksPostFeaturedMedia":{"thumbnail":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","medium_large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","1536x1536":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","2048x2048":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-small":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-small-tall":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-small-square":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-small-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-medium-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg","blogsy-wide":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg"},"magazineBlocksPostAuthor":{"name":"admin","avatar":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g"},"magazineBlocksPostCommentsNumber":"0","magazineBlocksPostExcerpt":"A war that began with airstrikes over Iran is now being felt in places far from the Middle East. On February 28, the US and Israel unleashed Operation Roaring Lion. Dramatic footage of missiles striking military, nuclear and government targets across Iran was broadcast around the world.But as the physical assault unfolded, another battle raged [&hellip;]","magazineBlocksPostCategories":["\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36"],"magazineBlocksPostViewCount":1,"magazineBlocksPostReadTime":12,"magazine_blocks_featured_image_url":{"full":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg",400,225,false],"medium":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg",300,169,false],"thumbnail":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/us-israel-iran-cyber-war.jpg",150,84,false]},"magazine_blocks_author":{"display_name":"admin","author_link":"https:\/\/koshalsambada.in\/author\/admin"},"magazine_blocks_comment":0,"magazine_blocks_author_image":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g","magazine_blocks_category":"<a href=\"#\" class=\"category-link category-link-31\">\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36<\/a>","_links":{"self":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/15015","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15015"}],"version-history":[{"count":0,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/15015\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/media\/15016"}],"wp:attachment":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}