logo

Cyber Retaliation: Analyzing Iranian Cyber Activity Following Operation Epic Fury

ID: 0c22fc5f-4224-56fe-86e0-2ae747e5295f

STIX ID: report--0c22fc5f-4224-56fe-86e0-2ae747e5295f

Feed Name: Tenable Blog

Threat Score
88/100

Date Published: 2026-03-11

Date Updated: 2026-05-01

Author: Research Special Operations

...
...

Tenable RSO reports that following Operation Epic Fury, Iranian-linked actors have shifted from espionage to coordinated disruptive and destructive campaigns—notably MuddyWater and Handala—using backdoors, custom wipers, and cybercriminal infrastructure to target critical sectors (finance, healthcare, energy, telecom, aviation). The analysis highlights active exploitation of high-severity CVEs (including multiple Hikvision/Dahua camera flaws and Microsoft vulnerabilities), claims of large-scale data exfiltration and device wiping, and an increased risk posture for organizations in affected industries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.