Full Report
And companies are getting caught in the crossfire interview Warfare has become a joint cyber-kinetic endeavor, with nations using cyber operations to scope out targets before launching missiles. And private companies, including shipping, transportation, and electronics manufacturers, are getting caught in the crossfire, according to Amazon.…
Analysis Summary
# Threat Actor: Imperial Kitten (UNC1549 / Smoke Sandstorm / APT35)
## Attribution & Identity
* **Attribution:** Operates on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC).
* **Aliases:** UNC1549, Smoke Sandstorm, APT35.
## Activity Summary
Imperial Kitten has been documented conducting cyber operations that directly preceded kinetic military strikes, representing a "cyber-kinetic endeavor."
* **December 2021:** Compromised a maritime vessel's Automatic Identification System (AIS) platform, gaining access to critical shipping infrastructure. Subsequently remediated with Amazon assistance.
* **August 2022:** Expanded targeting to additional ships, including breaching CCTV cameras aboard a vessel to gain real-time visual intelligence.
* **January - February 2024:** Conducted targeted searches for AIS location data for a specific vessel just before a Houthi missile strike against that ship on February 1, 2024, marking an unmistakable correlation between cyber reconnaissance and kinetic strike.
## Tactics, Techniques & Procedures
* **Digital Reconnaissance:** Used cyber operations to gather intelligence for physical targeting.
* **Infrastructure Compromise:** Gained access to core operational systems, including maritime AIS platforms.
* **Physical Surveillance Integration:** Compromised CCTV cameras aboard vessels to provide real-time visual reconnaissance data.
## Targeting
* **Sectors:** Shipping, maritime infrastructure.
* **Geography:** Associated with activities preceding strikes against vessels in international waters (implied Middle East region).
* **Victims:** Specific maritime vessels and shipping companies that possess valuable intelligence (AIS data, surveillance capabilities).
## Tools & Infrastructure
* **Specific Tools:** Not explicitly named, but leveraged access to **AIS platforms** and **CCTV camera systems**.
* **Infrastructure:** Cyber operations prepared the targeting environment for kinetic strikes.
## Implications
This actor exemplifies the "new operational model" where nation-state cyber operations are integrated directly into kinetic warfare planning. The targeting data collected digitally flows directly into physical decision-making, bridging the gap between traditional cyber attacks and conventional warfare. Companies previously thought immune to state-level targeting are now vulnerable if they possess location data, ICS, or surveillance systems.
## Mitigations
* **Holistic Threat Modeling:** Organizations must stop treating physical and digital security as separate domains; integrate risk management across both worlds.
* **Supply Chain Review:** Understand the physical location, shipping logistics, and physical storage access related to critical digital components.
* **System Security Assessment:** Scrutinize internet-connected physical control systems (e.g., building controls, industrial systems) to prevent them from being leveraged as intelligence tools.
---
# Threat Actor: MuddyWater (aka Mercury / Silent Bazar)
## Attribution & Identity
* **Attribution:** Government-backed cyber threat group linked to Iran's Ministry of Intelligence and Security (MOIS).
* **Aliases:** Seedworm, APT34, OilRig, TA450.
## Activity Summary
MuddyWater was observed provisioning cyber infrastructure that was subsequently used to conduct surveillance operations preceding physical strikes.
* **May 13 (Year Unspecified):** Provisioned a server specifically for a cyber campaign.
* **June 17 (Year Unspecified):** Used this infrastructure to access a compromised server containing live CCTV streams from Jerusalem.
* **June 23 (Year Unspecified):** This surveillance activity correlated with widespread Iranian missile attacks against Jerusalem on the same day, where authorities reported the exploitation of security cameras for real-time intelligence used to adjust missile targeting.
## Tactics, Techniques & Procedures
* **Infrastructure Staging:** Established dedicated server infrastructure in advance of operations.
* **Live Data Exploitation:** Accessed and leveraged live CCTV streams for real-time urban surveillance.
* **Integration with Kinetic Action:** Utilized surveillance data to adjust and refine missile targeting during active physical attacks.
## Targeting
* **Sectors:** General surveillance targets (cities, infrastructure).
* **Geography:** Jerusalem (mentioned specifically).
* **Victims:** Entities hosting publicly accessible or compromised real-time CCTV streams.
## Tools & Infrastructure
* **Infrastructure:** Provisioned cyber campaign servers; exploited compromised servers hosting live CCTV feeds.
## Implications
This actor demonstrates the use of cyber operations for tactical military advantage by optimizing strike accuracy through live intelligence gathering. This highlights the threat posed by groups linked to MOIS in urban conflict zones.
## Mitigations
* **Physical/Digital Convergence Focus:** Prioritize securing all externally facing and control systems that handle live visual or positional data.
* **Intelligence Sharing:** Improve communication between defense agencies and infrastructure operators regarding observed preparatory cyber activity.
---
# Threat Actor: Unnamed Russian Actor
## Attribution & Identity
* **Attribution:** State-sponsored actor linked to Russia.
* **Aliases:** Not specified in detail.
## Activity Summary
Reports indicate this actor engaged in cyber operations aimed at physical synchronization preceding kinetic action.
* **Activity:** Hacking into surveillance cameras to coordinate its attack on Kyiv.
## Tactics, Techniques & Procedures
* **Surveillance Acquisition:** Hacking oversight elements (surveillance cameras).
* **Coordination Role:** Directly linking digital access to tactical planning for ground/missile attacks.
## Targeting
* **Geography:** Kyiv.
* **Victims:** Organizations or municipal entities controlling surveillance camera networks in the target area.
## Tools & Infrastructure
* **Tools:** Exploited surveillance camera systems.
## Implications
Confirms that multiple state actors (Russia, alongside Iran) utilize cyber reconnaissance to coordinate physical military maneuvers, validating Amazon's assessment of a widespread global trend.
## Mitigations
* **General Cyber-Kinetic Resilience:** Apply the same cross-domain security principles recommended for Iranian actors to ensure critical domestic infrastructure (like public surveillance networks) is hardened against reconnaissance.
---
# Threat Actor: Unnamed Chinese Actor
## Attribution & Identity
* **Attribution:** State-sponsored actor linked to China (PRC).
* **Aliases:** Not specified in detail; referred to as showing a pattern of combining intelligence gathering and physical world attacks.
## Activity Summary
This group is reportedly continuing a long-term pattern of intentionally combining intelligence gathering with physical world attacks, as evidenced by a public example involving compromise of a sensitive facility (details regarding the specific facility were redacted/missing in the provided excerpt).
## Tactics, Techniques & Procedures
* **Combined Operations:** Intentional merging of digital espionage/intelligence gathering with physical world attacks.
## Targeting
* **Victims:** Not explicitly detailed, but one public example involving a compromise of a specific facility was cited.
## Implications
Suggests that China’s cyber strategy consistently views digital access as an enabling factor for kinetic or physical impact operations.
## Mitigations
* **Expanded Threat Model:** Defense strategies must account for persistent, long-term Chinese cyber operations aimed at building intelligence caches for future physical action.