



















Email spoofing, denying people access to web services of airports and banks, and hacking into CCTV networks in enemy territories – the West Asia war has spilled over to cyberspace, causing enormous damage to networks and services.
Even as missiles from underground missile cities in Iran and airstrikes by Israel and the United States rattle West Asia over the last six weeks, cybersecurity experts see this war spilling over to the cyber world, threatening to cause heavy losses to governments, enterprises, and businesses.
While Israel reportedly hacked into CCTV camera networks in the Iranian capital, Tehran, to keep tabs on its targets, Iran tapped into vulnerabilities in various Gulf locations to have an ‘eye’ on its targets.
While Iran’s missile arsenal, which has been tucked deep in missile cities under mountains, surprised the world, its ‘preparedness’ with regard to cyber ‘ammunition’ equally surprised cybersecurity experts by surging into overdrive through pre-planted backdoors and state-directed APT groups despite domestic Internet blackouts.
Though Iran’s Internet collapsed to 1-4 per cent of its pre-war capacities within hours after the US and Israel launched airstrikes in late February, its cyber apparatus surged into overdrive through pre-planted backdoors, overseas infrastructure, and state-directed APT (Advanced Persistent Threat) groups that never missed a beat, according to cybersecurity company Seqrite.
“Iran’s cyber response has been ruthlessly effective despite domestic blackouts. Seedworm/MuddyWater (MOIS-linked) was already inside US and Israeli networks pre-strikes, deploying Dindoor (Deno-based backdoor) and Fakeset (Python implant) signed with stolen certificates against banks, airports, and non-governmental organisations,” it said.
At the same time, an APT group linked to Iran executed credential phishing against US think tanks using OneDrive lures and another spoofed Iraqi government email addresses in ClickFix attacks.
Seqrite says one group expanded camera scanning across Gulf states, exploiting flaws to enable real-time strike damage assessment, while another group remotely wiped over 2 lakh devices at a corporate entity.
Over 50 hacktivist groups collaborated over social media and launched DDoS (distributed denial of services) attacks on airports and banks in the Gulf and Israeli infrastructure. Most of these attacks remain low-impact noise atop sophisticated state operations.
As the Iran-US-Israel conflict triggers a multi-vector cyber offensive, Seqrite has appealed to global and Indian enterprises to build defences to get ready for AI-assisted espionage, wiper attacks, and State-sponsored digital warfare.
Global cybersecurity solutions company Sophos felt that Iranian‑linked threat groups often use a core set of initial access methods.
“The threat actors favour cost-effective, repeatable intrusion techniques that involve social engineering, quickly exploiting public vulnerabilities, and using compromised credentials to infiltrate systems,” it said in an advisory in March.
To build strong defence measures, organisations should reinforce identity, email, and perimeter security by implementing phishing-resistant multi-factor authentication, promptly patching exposed systems, monitoring for unusual authentication and remote management activity, and minimising the risk posed by weak or default credentials.
Shikha Sangwan, Senior Security Research Engineer at Securonix, pointed out that periods of geopolitical tensions and operational pressure often create the very conditions in which sophisticated and opportunistic threat actors thrive.
“When organisations are focused on maintaining continuity, even small gaps such as incomplete telemetry or reduced monitoring capacity can give adversaries all they need to move silently and undetected,” Sangwan said.
Tarun Wig, Co-Founder and CEO of New Delhi-based Innefu Labs, said that modern conflicts are no longer confined to battlefields but unfold simultaneously across various domains, such as maritime, cyberspace, and information ecosystem warfare.
Tactics such as GPS jamming and creating ghost ships to mislead tracking systems (Automated Identification Systems) show that digital interference is now integrated into naval strategy.
“AI-based intelligence platforms help defence analysts correlate satellite imagery, vessel movement patterns, electronic interference signals and open-source intelligence in real time,” he said.
Published on April 12, 2026
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。