Technology & OSINT — 2026-03-20

Unit 42: Iranian Cyber Threat Actors Expanding Beyond Espionage to Destructive Operations

Unit 42's threat brief documents Iranian cyber actors' shift from espionage-focused operations to destructive attacks targeting critical infrastructure and defense industrial base entities. The analysis notes increased use of wiper malware, supply chain compromises, and credential harvesting via infostealers -- the same TTP used in the Stryker/Handala attack. The brief assesses Iranian cyber capacity as a persistent compensatory tool for degraded conventional military capability.

View in full brief →

UNCLASSIFIED // OPEN SOURCE