Cyber Operations & Adversary IC — 2026-04-02

BeyondTrust Threat Advisory Maps Iran-Aligned Cyber Actor Response to Operation Epic Fury Across Five Operational Domains

BeyondTrust published a threat advisory mapping Iran-aligned cyber actor responses to Operation Epic Fury across five operational domains: state-sponsored APT espionage, IRGC-CEC infrastructure attacks, MOIS-directed hacktivist operations, ransomware proxy campaigns, and information warfare. The advisory identifies CyberAv3ngers as the primary threat to U.S. critical infrastructure through exploitation of OT/ICS systems with default credentials. The analysis distinguishes between MOIS (Handala, APT34) and IRGC-CEC (CyberAv3ngers, APT33) organizational chains, noting the two operate as strategically aligned but organizationally separate campaigns with distinct TTPs and target sets.

1 sources
  1. Threat Advisory: Iran-Aligned Cyber Actors Respond to Operation Epic Fury - BeyondTrust

View in full brief →

UNCLASSIFIED // OPEN SOURCE