Five days after the start of the war between the US and Israel with Iran, the worst predictions for Iranian cyber attacks have not yet materialized. However, Iran has developed one of the most active cyber operations in the world, which means this is likely a temporary lull, experts warn. Over the weekend, both the UK National Cyber Security Centre (NCSC) and the Canadian Cyber Security Centre (CCCS) issued general warnings about the threat posed by Iranian cyber campaigns.
See also: Trump's War with Iran: Impact on Energy Prices

In the meantime, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has not yet updated its latest advisory since October.
The service urged organizations to look beyond the background noise of opportunistic DDoS attacks and other low‑level cyber activities for darker threats such as ransomware and destructive wiper attacks. The general nature of the warnings underscores the problem of alert fatigue: If Iranian cyber attacks are a continuous threat, what should organizations pay attention to?
Does this change with the arrival of war or does it simply change its schedule? Security companies rarely hesitate to publicize Iranian threats. Nevertheless, the consensus is that Iranian cyber retaliation has so far been surprisingly mild.
This may simply be an adjustment period caused by the disruption of Iran's energy and internet infrastructure, they warn. To date, the active groups are divided into three overlapping categories: those primarily targeting Middle Eastern infrastructure, those oriented towards targets in the West — which include specialized advanced persistent threat (APT) groups — and smaller proxies based outside Iran whose targeting is unpredictable.
On March 2, Palo Alto’s Unit 42 reported, “State-aligned cyber units may operate in operational isolation, which could lead to deviations from previously established patterns. Furthermore, the degradation of Iranian command and control may also lead to tactical autonomy for cells outside of Iran.” DDoS represents the greatest immediate threat to Iranian cyberattacks.
See also: The Cyber-Kinetic Warfare Escalation between Iran and the US

So far, this hasn’t happened on any scale, with Cloudflare CEO Mathew Princetweeting on X on Sunday that DDoS attacks linked to Iran were actually down. This is despite reports from CrowdStrike that the Hydro Kitten group had issued DDoS threats against the US banking sector, which led to short-term disruption. Security firm Radware detected 149 DDoS attacks that appeared to be linked to Iran between February 28 and March 2, most of which targeted government entities in the Middle East.
All but a small percentage were led by just three hacker groups, Keymous+, DieNet and Conquerors Electronic Army, the company said. Devastating “wiper” attacks are a more pressing concern. The precedent for this is the infamous Iranian Shamoon of 2012 that wiped out 30,000 workstations at oil company Saudi Aramco. While subsequent Iranian cyberattack attempts have also targeted the energy sector, the risk is that in times of war any target will do, in the US or elsewhere.
The biggest concerns are the high-profile APT groups linked to the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS) that have a proven track record of attacks. This includes APT35/APT42 (Charming Kitten, Phosphorous) and APT33 (Elfin Team). Interestingly, one of the most active Iranian APTs, APT34 (OilRig), appears to have gone silent, as it has not been observed for a week.
Security firm Tenable has published a helpful summary of the most prominent Iranian threat groups that discusses the tools, techniques, and processes of each. According to Adrian Cheek, senior cybercrime researcher at Canadian threat intelligence firm Flare, the most vulnerable sectors are critical infrastructure, including the defense and government supply chain, financial services, energy, and healthcare.
See also: Iranian Cyber Front: Increased activity by hacktivists

Organizations must urgently monitor for wiper malware, while ensuring that endpoint systems are ready to detect variants of Shamoon and repairing the VPN and other edge devices, another favorite Iranian target.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
