Skip to content
Data Breach

Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption

Iran-linked hackers are not relying only on loud attacks, public leaks, or website defacements. They are quietly building access inside companies, cloud accounts, service providers, and industrial networks that could later be used to disrupt operations during a crisis. The activity includes stolen c...

· Jul 22, 2026 · 3 min read · 👁 4 views
Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption

Iran-linked hackers are not relying only on loud attacks, public leaks, or website defacements.

They are quietly building access inside companies, cloud accounts, service providers, and industrial networks that could later be used to disrupt operations during a crisis.

The activity includes stolen credentials, remote management tools, recruitment-themed phishing, and attacks on exposed industrial systems.

Recent reporting on Iranian infrastructure breaches involving backdoors shows how an initial foothold can give attackers a path to sensitive systems and trusted administrators.

SentinelOne said in a report shared with Cyber Security News (CSN) that they noted the biggest danger is not always an immediate destructive attack.

It is the option to use previously gained access for intelligence gathering, data theft, pressure campaigns, or selective disruption when political conditions change.

Iranian Hackers Are Quietly Building Access

The report describes this strategy as “access optionality.” A compromised account, an IT supplier, or a remote administration tool may initially be used for spying, but it can become a way to interrupt business operations later.

Iran-linked activity should not be viewed as one unified operation. Different groups and public-facing personas have separate missions, targets, and levels of technical ability, even when their campaigns appear connected.

The MOIS-linked Seedworm, also known as MuddyWater, was linked to intrusions affecting a U.S. bank, airport, nonprofits, and an Israeli operation of a U.S. software supplier.

Researchers found multiple backdoors and an attempted transfer of data to commercial cloud storage, while Seedworm’s signed software abuse campaign highlights the group’s continuing focus on long-term access.

The report also points to Screening Serpens activity that used tailored recruitment lures to deploy remote-access tools against targets in the United States, Israel, the UAE, and other Middle East countries.

Handala’s original Wiper claim against Stryker (Source - SentinelOne)
Handala’s original Wiper claim against Stryker (Source – SentinelOne)

These lures often target people with trusted roles, where one compromised account can expose internal conversations, contacts, and cloud resources.

Service providers are another important route. Attackers can misuse access already granted to an administrator, support company, identity provider, or remote management platform, making strong remote access security controls essential for organizations that depend on outside IT support.

Industrial Systems Face Pressure

The most serious consequences can arise when attackers reach operational technology, including systems used by water utilities, energy providers, factories, and government facilities.

The report says Iranian-affiliated actors have targeted internet-facing Rockwell Automation and Allen-Bradley programmable logic controllers, with some incidents causing operational disruption and financial losses.

This threat does not mean every exposed industrial dashboard has been fully controlled or that every public claim is accurate.

Researchers stressed that evidence should distinguish between seeing a login page, accessing a live interface, changing settings, and causing a real-world process effect.

Affected ATM (Source - SentinelOne)
Affected ATM (Source – SentinelOne)

Still, exposed systems create unnecessary risk. Recent warnings about internet-facing industrial PLC weaknesses reinforce the need to remove direct internet access, replace default credentials, enforce phishing-resistant multi-factor authentication, and separate business networks from operational controls.

Organizations should also restrict vendor access by time, source, and role; monitor engineering workstations and industrial communications; and preserve offline copies of approved configurations.

Recovery systems must be tested separately because backups that share the same identity tools or administrators as production networks can fail during the same incident.

Iran-linked operators are likely to continue gathering intelligence while using public personas to amplify claims, leak material, and create pressure before the technical impact is fully understood.

The immediate priority for defenders is to identify trusted access paths now, before an ordinary account compromise becomes wartime leverage.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you