Full Report
Iran state media on Monday said a ballistic missile with improved capabilities was demonstrating a new doctrine: Tehran “will take action against any threat, even before it is carried out.” The report by Iran’s state news agency repeatedly cited comments aired on state TV the day before by the head of Iran’s Supreme National Security Council, Mohsen…
Analysis Summary
# Threat Actor: Islamic Revolutionary Guard Corps (IRGC) / Tehran State Actors
## Attribution & Identity
* **Primary Actor:** Islamic Revolutionary Guard Corps (IRGC)
* **State Affiliation:** Iran
* **Key Individuals:** Mohsen Rezaei (Head of Iran’s Supreme National Security Council)
* **Associated Groups:** Unidentified Iranian hackers (referenced in associated Texas AT&T outage claims)
## Activity Summary
* **Kinetic Operations:** In September 2026, the IRGC launched ballistic missiles targeting two U.S. Navy warships patrolling regional waters. This followed six months of attacks previously restricted to commercial shipping.
* **Cyber Operations:** Iranian-linked hackers claimed responsibility for a significant AT&T outage in Texas, threatening intensified attacks leading up to September 11.
* **Doctrine Shift:** Iranian state media announced a new "preemptive action" doctrine, stating Tehran will take action against perceived threats before they are carried out.
## Tactics, Techniques & Procedures
* **Kinetic Engagement:** Deployment of solid-fueled ballistic missiles against naval targets.
* **Preemptive Strike Doctrine:** Public signaling of a shift from reactive to proactive military engagement.
* **Critical Infrastructure Targeting:** Claims of disrupting telecommunications via cyber means to cause civilian impact.
* **Psychological Operations (PSYOPS):** Use of state media and social media to vow "intensified" attacks around symbolic dates (e.g., 9/11).
## Targeting
* **Sectors:** Defense (Maritime), Communications (Telecommunications), Critical Infrastructure (Water/Energy mentioned as high-risk areas).
* **Geography:** Middle East (Strait of Hormuz/Regional waters), United States (Texas).
* **Victims:** U.S. Navy warships, AT&T (claimed), commercial shipping vessels.
## Tools & Infrastructure
* **Ballistic Missiles:** Qassem Basir (solid-fueled variant).
* **Unmanned Systems:** Drones (referenced in broader regional context).
* **Cyber Tools:** Specific malware families were not named in this report, but activity focused on infrastructure disruption.
## Implications
The transition to a "preemptive" doctrine represents a significant escalation in Iranian military strategy. By targeting U.S. military assets directly rather than just commercial shipping, the IRGC is signaling a higher tolerance for direct conflict. The synchronization of kinetic maritime threats with domestic U.S. cyber disruptions (e.g., AT&T) suggests a multi-domain pressure campaign intended to influence U.S. policy and regional presence.
## Mitigations
* **Maritime Defense:** Continued deployment of Aegis-equipped warships and integrated air defense systems to intercept ballistic threats in the Strait of Hormuz.
* **Cyber Resilience:** Hardening of U.S. critical infrastructure, specifically telecommunications and water sectors, against state-sponsored disruption.
* **Enhanced Monitoring:** Increased intelligence surveillance of IRGC missile launch sites and solid-fuel production facilities.
* **Incident Response:** Critical infrastructure providers should prepare for "intensified" activity windows surrounding symbolic anniversaries.