For months now, Iranian state-sponsored hackers have been the target of a series of attacks. These attacks have resulted in the theft of parts of online infrastructure and the leaking of important secrets around the world. This has left them particularly vulnerable, especially at a time when tensions with the West are constantly rising.
Iran has carried out many cyberattacks on America. It is something like electronic warfare. Researchers have identified several gangs linked to Iran. The Oil Rig group, equivalent to Russia's Fancy Bear, infiltrates networks mainly through phishing attacks. The Newscaster group specializes in impersonating social engineering platformsto get closer to a target. Elfin and APT33 carry out more “violent” attacks. In November, such an attack took place on an Italian company.
However, there have been no reports of any major attacks by Iranian hackers in the past two months. This is not necessarily reassuring. Security are cautious and believe that an attack could occur at any time.
What has probably stopped, at least temporarily, the Iranians' activities are the attacks they are receiving from all over the world. For example, in November, security companies discovered one of their secret hacking campaigns, known as DNSpionage.

According to the researchers, Iranian hackers do not have the resources of other hacking groups in the US, China and Russia, but their attacks are well-planned. They are not so good at neutralizing a well-protected system, but they are very good at finding the point where it is not well-protected and launching an attack.
Since DNSpionage was revealed, a series of other revelations related to the secret activities of hackers began.
In February, Iranian hackers were charged with spying on American military personnel, with the help of Monica Witt, a former US Air Force officer.
The following month, Microsoft hit the Oil Rig group in a sensitive spot: the addresses used by hackers in their phishing attacks . In fact, it denounced the group and managed to take control of 99 of the domains used by the hackers to scam their victims.
A few months later, a mysterious channel on Telegram put hackers in an even more difficult position.
“We expose here the hacking capabilities that Iranian hackers have and use to achieve their evil purposes,” the channel said. “These capabilities include expertise in databases, Internet service providers, programming languages, social engineering, etc. Hackers use these capabilities to spy on innocent compatriots… It is time to crush them.”.
After that, the anonymous channel operators revealed a lot of information about the tactics, tools, and goals of the Oil Rig group. They also revealed the source code of the group's malware, a list of the systems they have compromised, names and other personal information of the group members, and the IP addresses of their servers.
These revelations certainly have major implications for Iranian hackers.
Despite the difficulties, however, no one doubts that they are still capable of carrying out attacks that can cause serious damage.
