Full Report
The geopolitical landscape of the Middle East has entered one of its most volatile phases in decades. On February 28, 2026, tensions that had been simmering for years erupted into a full‑blown conflict involving the Islamic Republic of Iran, the United States, and Israel. A confluence of diplomatic stalemate, military posturing, and covert cyber preparations set the stage for what would evolve from a localized confrontation into an expansive, multi‑domain campaign. The conflict’s opening salvo — codenamed Operation Epic Fury by the US and Operation Roaring Lion by Israel — was not just a conventional military assault. It was a synchronized hybrid offensive in which cyber operations were integrated as a co‑equal domain with kinetic strikes, psychological messaging, and information warfare. Over the course of the first 72 hours, from February 28 to March 3, kinetic blows and digital disruptions merged in ways that revealed both the strengths and vulnerabilities of actors across the region. Throughout this critical period, Cyble Research and Intelligence Labs (CRIL) has been meticulously tracking the movements, attacks, claims, and associated cyber activity between Iran, Israel, and the US, providing real‑time insights into both the kinetic strikes and the evolving threat landscape. Prelude to Conflict: Buildup and Diplomatic Gridlock In the days leading up to February 28, the Middle East witnessed a massive US military buildup, the largest since the 2003 Iraq invasion. Aircraft carriers, fighter wings, and intelligence assets positioned themselves within striking range of Iran’s borders. At the same time, indirect nuclear negotiations in Geneva appeared, momentarily, to offer a diplomatic pathway, with Iran publicly agreeing to halt enrichment stockpiling under International Atomic Energy Agency (IAEA) supervision. However, distrust and strategic imperatives among the US, Israel, and Tehran rendered the diplomatic exercise insufficient to prevent escalation. Day 1: February 28 — Operation Epic Fury At approximately 06:27 GMT, the first concerted wave of strikes hit Iran. US‑Israeli forces began a broad assault across more than two dozen provinces, targeting nuclear facilities, IRGC command centers, ballistic missile launchers, and secure compounds tied to the Iranian leadership. The offensive reportedly included the targeted killing of Supreme Leader Ayatollah Ali Khamenei, a moment that marked a profound turning point in the conflict. What set the opening apart from traditional air campaigns was its immediate cyber component. For the first time on such a scale, network disruption was planned to coincide with a kinetic impact. Independent monitors observed Iranian internet connectivity collapse to roughly 1–4% of normal levels as cyberattacks crippled state media, government digital services, and military communications. Popular local services, including widely used mobile applications and prayer tools, were reportedly compromised to sow confusion and prompt defections, while defaced state news sites delivered messages contradicting official Iranian narratives. Before the current situation, MuddyWater, long associated with Iran‑linked cyber campaigns, remained a critical piece of the pre‑existing threat landscape. Alongside other advanced persistent threat (APT) groups — such as APT42 (Charming Kitten), Prince of Persia / Infy, UNC6446, and CRESCENTHARVEST — these campaigns had already been active before February 28, conducting phishing, exploitation of public servers, and information theft targeting Israeli, US, and regional networks. While Iran’s domestic internet infrastructure faltered, the US‑Israeli offensive extended psychological operations into Israeli territory. Threatening messages referencing national ID numbers and fuel shortages arrived in civilians’ inboxes, and misinformation campaigns amplified anxieties even as authorities worked to blunt digital interference. Day 2: March 1 — Retaliation and the Surge of Hacktivism Iran’s kinetic retaliation was swift and forceful. From March 1 onward, waves of ballistic missiles and drones launched at Israel, Gulf Cooperation Council (GCC) states, and US military bases reinforced that Tehran’s response would not be limited to symbolic posturing. The UAE alone intercepted hundreds of projectiles, resulting in civilian casualties and infrastructure damage, including at Dubai’s international airport and an AWS cloud data center within its mec1‑az2 availability zone. On the cyber front, March 1 started the dramatic expansion of hacktivist activity across the region. More than 70 groups — spanning ideological spectrums and even blending pro‑Iranian and pro‑Russian motivations — activated operations in parallel with state responses. An Electronic Operations Room organized by Iraqi‑aligned hackers, such as Cyber Islamic Resistance / Team 313 began orchestrating distributed denial‑of‑service (DDoS) attacks, website defacements, and theft of credentials across national government portals and key infrastructure systems in Turkey, Poland, and GCC states. One of the most technically significant artifacts of March 1 was a malicious RedAlert APK observed by Unit 42 analysts. Designed to mimic Israel’s official missile alert app, this payload was distributed via Hebrew‑language SMS links. Once installed, it collected sensitive device and user information — contacts, SMS logs, IMEI numbers, and email credentials — with encrypted exfiltration mechanisms and anti‑analysis protections, providing a rare glimpse of tradecraft resembling state‑level cyber operations at a time when Iranian domestic internet access was severely limited. Beyond MuddyWater and other established APTs, opportunistic cybercriminals exploited the chaos through social engineering campaigns in the UAE. Day 3: March 2–3 — Strikes, Blackouts, and Enduring Hybrid Threats The kinetic campaign broadened on March 2 with the destruction of the IRGC’s Malek‑Ashtar headquarters in Tehran. By March 3, Israeli forces had struck Iran’s state broadcaster, further constraining Tehran’s ability to manage domestic information and cyber operations. The extended internet blackout — persisting well into the third day — continued to isolate Iranian networks, allowing external campaigns to operate with limited interference. Several digital fronts emerged during this period: Hacktivist and Propaganda Operations: Groups such as Handala Hack Team claimed exfiltration of terabytes of financial data; others like DieNet and OverFlame targeted GCC critical infrastructure portals and governmental systems in coordinated disruptive campaigns. Pro‑Russian Opportunistic Convergence: Entities, including NoName057(16) and Russian Legion, shifted their focus from Ukraine‑related operations to anti‑Israel actions supportive of Iran, albeit with mixed credibility. Cybercrime Opportunism: The blend of hacktivism and ransomware was exemplified by groups like INC Ransomware, which targeted industrial entities and combined extortion‑style tactics with ideological messaging. Throughout March 1–3, analysts noted that most observed cyber activity fell into the realm of DDoS attacks, exposed CCTV feeds, and information operations rather than destructive intrusions into industrial control systems — although unverified claims of SCADA manipulation circulated widely in pro‑Iranian forums. Broader Regional and Strategic Implications The first 72 hours of Operation Epic Fury reveal several critical insights about modern conflict dynamics in the Middle East: Cyber as a Co‑Equal Domain: Cyber operations were planned and executed in lockstep with kinetic strikes, demonstrating that modern warfare no longer segregates digital and physical arenas. Hacktivist Amplification: With over 70 groups active within days, the hacktivist ecosystem has become a force multiplier of psychological and disruptive operations that can transcend national borders. Opportunistic Exploitation: As seen in social engineering and ransomware campaigns, broader conflict can catalyze financially motivated cybercrime that piggybacks on geopolitical uncertainty. These dynamics suggest that defenders in the region — from government CERTs to multinational enterprises — must maintain heightened vigilance across both technical and psychological threat vectors, with particular emphasis on credential harvesting, DDoS mitigation, and proactive monitoring of emerging malware campaigns. Conclusion The events from February 28 to March 3 highlight that the US‑Israeli offensive against Iran — launched as Operation Epic Fury — is not merely a military confrontation but a hybrid engagement across kinetic, cyber, and informational domains. While Iran’s internet infrastructure remains degraded, sophisticated pre‑positioned capabilities could still be activated in the coming weeks, particularly if connectivity is restored. Meanwhile, the hacktivist theatre continues to grow in both volume and geographic scope, even as the technical sophistication of most operations remains limited. In this environment, security practitioners and strategic planners must be prepared for adaptive threat behavior that blends political motivations with opportunistic cybercrime — a reality that defines the 21st‑century battlespace in the Middle East and beyond. References: https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ https://www.sophos.com/en-us/blog/cyber-advisory-increased-cyber-risk-amid-u-s-israel-iran-escalation https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east https://www.cybersecuritydive.com/news/iran-hackers-threat-level-us-allies/813494/ https://flashpoint.io/blog/escalation-in-the-middle-east-operation-epic-fury/ https://www.anomali.com/blog/cyber-threat-briefing-iran-retaliatory-posture https://blog.checkpoint.com/research/what-defenders-need-to-know-about-irans-cyber-capabilities/ https://www.khaleejtimes.com/uae/dubai-police-warn-scammers-impersonating-government-officials The post Middle East on the Brink: Iran-US-Israel Hostilities Trigger Cyber-Kinetic Conflict appeared first on Cyble.
Analysis Summary
# Incident Report: Operation Epic Fury / Roaring Lion Hybrid Conflict
## Executive Summary
Between February 28 and March 3, 2026, a massive hybrid military and cyber offensive was launched by US and Israeli forces against Iran, codenamed Operation Epic Fury and Operation Roaring Lion. The escalation featured the synchronization of kinetic strikes on critical infrastructure with a near-total collapse of Iranian internet connectivity and widespread hacktivism. The multi-domain conflict resulted in significant regional disruption, including the targeting of energy infrastructure, government services, and cloud data centers across the Middle East.
## Incident Details
- **Discovery Date:** February 28, 2026
- **Incident Date:** February 28, 2026 – March 3, 2026
- **Affected Organization:** Multiple (IRGC, Iranian State Media, AWS, GCC Government Portals)
- **Sector:** Government, Defense, Energy, Telecommunications, and Technology
- **Geography:** Iran, Israel, UAE (GCC), USA
## Timeline of Events
### Initial Access
- **Date/Time:** February 28, 2026, 06:27 GMT
- **Vector:** Pre-positioned APT implants, massive DDoS, and kinetic destruction of infrastructure.
- **Details:** Synchronized air strikes on command centers coincided with a collapse of Iranian internet connectivity to 1–4% of normal levels.
### Lateral Movement
- Coordination between over 70 hacktivist groups (e.g., Team 313) moving across national government portals in Turkey, Poland, and GCC states.
- High-volume credential harvesting via malicious mobile applications (RedAlert APK).
### Data Exfiltration/Impact
- **Terabytes of data:** Handala Hack Team claimed exfiltration of financial data.
- **Infrastructure Damage:** Destruction of IRGC Malek-Ashtar headquarters; strikes on the AWS mec1-az2 data center in UAE.
- **Information Ops:** Defacement of Iranian state news sites to deliver counter-narratives.
### Detection & Response
- **Discovery:** Real-time monitoring by Cyble Research and Intelligence Labs (CRIL) and Unit 42.
- **Response:** Interception of hundreds of projectiles by UAE defenses; lockdown of digital infrastructure by regional CERTs.
## Attack Methodology
- **Initial Access:** Phishing, exploitation of public-facing servers, and malicious mobile application lures (RedAlert APK).
- **Persistence:** Pre-existing APT activity (MuddyWater, APT42, Infy) positioned well before the kinetic start date.
- **Defense Evasion:** Use of encrypted exfiltration mechanisms and anti-analysis protections in custom Android malware.
- **Credential Access:** Credential harvesting via fake missile alert apps and social engineering in the UAE.
- **Lateral Movement:** Orchestrated "Electronic Operations Rooms" by Iraqi-aligned hackers for cross-border pivoting.
- **Exfiltration:** High-volume data theft by hacktivist collectives disguised as ideological "leaks."
- **Impact:** Integration of DDoS, ransomware (INC Ransomware), and kinetic strikes to achieve total "Information Blackout."
## Impact Assessment
- **Financial:** Significant, including crypto-extortion attempts by INC Ransomware and industrial disruption.
- **Data Breach:** Compromise of national ID numbers, financial logs, and government credentials.
- **Operational:** Iranian domestic services (prayer tools, mobile apps, state media) rendered non-functional for 72+ hours.
- **Reputational:** High-profile defacements and the targeted killing of leadership fundamentally challenged state authority.
## Indicators of Compromise
- **Network:** Monitoring for peaks in DDoS traffic targeting port 80/443 of GCC government portals.
- **File:** RedAlert.apk (Malicious Android package mimicking missile alerts).
- **Behavioral:** Sudden drops in BGP routing/connectivity (1-4% threshold); SMS-based lures in Hebrew/Arabic directing to credential harvesting sites.
## Response Actions
- **Containment:** Intentional internet blackouts and network isolation to prevent further external interference.
- **Eradication:** Neutralization of IRGC command-and-control (C2) nodes.
- **Recovery:** Restoration of basic digital services and internet connectivity via satellite or hardened terrestrial links.
## Lessons Learned
- **Cyber-Kinetic Convergence:** Cyber is now a "co-equal" domain; digital disruption is timed specifically to amplify the psychological impact of physical strikes.
- **Hacktivist Proliferation:** Ideological groups act as force multipliers, complicating the attribution landscape between state and non-state actors.
- **Cloud Vulnerability:** Physical strikes on data centers (AWS mec1-az2) prove that "the cloud" remains a physical target with regional ripple effects.
## Recommendations
- **Multi-Vector Defense:** Organizations must monitor both technical IOCs and psychological information operations.
- **DDoS Resilience:** Implement robust mitigation for government and critical infrastructure portals.
- **Mobile Security:** Educate users against sideloading applications (like fake alert apps) during periods of high geopolitical tension.
- **Credential Hygiene:** Mass reset of credentials following observed large-scale harvesting campaigns in the GCC.
***
*Note: References for this report include hxxps[://]unit42[.]paloaltonetworks[.]com/iranian-cyberattacks-2026/ and hxxps[://]cyble[.]com/blog/middle-east-iran-us-israel-hybrid-conflict/.*