Technology & OSINT — 2026-03-25

ESET Assessment: Iran War Driving Unprecedented Convergence of State APTs and Hacktivists Against Western Infrastructure

ESET security writer Tomas Foltyn published an assessment documenting the convergence of Iran's state-sponsored APT groups (MuddyWater, OilRig, CyberAv3ngers) with opportunistic hacktivist collectives in targeting Western commercial and critical infrastructure. Key incidents cited include Iranian drone strikes on three AWS facilities in the UAE and Bahrain on March 1 that disrupted cloud services, and the Handala group's data-wiping attack on Stryker Corporation on March 12 that caused global system shutdowns. The analysis warns that 'some tactics can be deployed in tandem: a website defacement or DDoS attack that looks like a nuisance-level hacktivist operation might be a deliberate distraction' masking more sophisticated state-directed intrusions. Physical distance provides no protection; organizations with supply chain relationships to the Middle East or dependencies on regional cloud infrastructure face disproportionate risk.

Analysis
Prior briefs tracked the AQ Cyber Jihad Movement's entry into Iran's hacktivist ecosystem and the Stryker wiper attack. The ESET assessment adds the AWS infrastructure strikes as a new vector: kinetic attacks on cloud providers affect global customers far beyond the theater of operations. CISA's one-third staffing level during this threat peak is the most consequential gap.
1 sources
  1. What the Iran war means for cybersecurity risks - Security MEA (ESET)

View in full brief →

UNCLASSIFIED // OPEN SOURCE