ESET Assessment: Iran War Driving Unprecedented Convergence of State APTs and Hacktivists Against Western Infrastructure
ESET security writer Tomas Foltyn published an assessment documenting the convergence of Iran's state-sponsored APT groups (MuddyWater, OilRig, CyberAv3ngers) with opportunistic hacktivist collectives in targeting Western commercial and critical infrastructure. Key incidents cited include Iranian drone strikes on three AWS facilities in the UAE and Bahrain on March 1 that disrupted cloud services, and the
Prior briefs tracked the AQ Cyber Jihad Movement's entry into Iran's hacktivist ecosystem and the Stryker wiper attack. The ESET assessment adds the AWS infrastructure strikes as a new vector: kinetic attacks on cloud providers affect global customers far beyond the theater of operations. CISA's one-third staffing level during this threat peak is the most consequential gap.
1 sources
- What the Iran war means for cybersecurity risks - Security MEA (ESET)