Cybersecurity & Privacy — 2026-03-21

Unit 42: Iranian Cyber Actors Expanding From Espionage to Destructive Operations Against US Targets

Unit 42's threat brief documents Iranian cyber groups -- CyberAv3ngers, APT33, APT55 under IRGC and MuddyWater, APT34 under MOIS -- transitioning from espionage to destructive operations targeting US industrial control systems including water treatment plants and power grids. The escalation reflects Iran's use of cyber as asymmetric leverage during conventional military disadvantage.

View in full brief →

UNCLASSIFIED // OPEN SOURCE