INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Iran-linked Hackers Target Critical Infrastructure

| 2026-08-25 18:17 MEDIUM LOW STATE-SPONSORED & ESPIONAGE CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
The US Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of a whole-of-government economic campaign aimed at crippling their ability to disrupt global critical infrastructure. The sanctions target nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including digital assets sectors. This multi-pronged threat comprises various clusters with distinct mission, targeting, and tradecraft, as revealed by SentinelOne. The Treasury's move is part of a broader effort to disrupt Iranian financial connections worldwide, attributed to the country's Ministry of Intelligence and Security (MOIS) behind extensive compromises of US critical infrastructure entities and financially motivated cyber theft.
Technical Mitigations AI-generated
* Implement robust encryption protocols, such as AES-256 or RSA-4096, to protect sensitive data from unauthorized access. * Conduct regular security audits and penetration testing to identify vulnerabilities in systems and networks. * Utilize secure communication channels, like end-to-end encrypted messaging apps (e.g., Signal), for sensitive information exchange. * Implement multi-factor authentication (MFA) with strong passwords and biometric authentication whenever possible.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

bc•••••.monster
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Economic OutcastOperation Economic Outcast
Target & Sectors
NORTH_AMERICA NORTH_AMERICA cryptocurrencycryptocurrency defensedefense educationeducation energyenergy governmentgovernment maritimemaritime technologytechnology
Incident Timeline
‎at least 2013
The 17 hacktivist group used malware to target at least 42 US-based private sector companies, including five US federal and state government agencies.
industry Government
target_region United States
attribution DoJ
general_metric 17 DoJ
general_metric 144 based universities
general_metric 178 foreign universities
victims 42 based sector companies
victims 11 sector companies
‎January 6, 2018
Threat actors used stolen US government personnel access to target Iranian companies.
‎between January 6, 2018
Keyvan Fayyaz Ghareh Blagh, a blockchain analytics firm, added 10 cryptocurrency addresses with cumulative value of $15.5 million between January 2018 and August 2026.
general_metric 10 addresses
general_metric 15.5 addresses
general_metric 92 %
‎July 12, 2019
Threat actors used stolen US government data to target Iranian hackers.
‎between July 12, 2019
Threat actors used cryptocurrency transactions to transfer $1.2 million from 15 wallet addresses associated with Behzad Mesri between July 12, 2019 and August 22, 2026.
general_metric 15 wallet addresses
financial $1.2 Mesri
‎at least late 2023
Keyvan Fayyaz Ghareh Blagh and Saber Shahbazi Balujeh are accused of conducting network compromise activity targeting U.S. critical infrastructure sector companies, including energy, defense, healthcare, technology, and financial institutions since at least late 2023.
industry Energy
industry Defense
industry Healthcare
industry Technology
‎summer 2023
Arman Kahzadian used a cryptocurrency wallet worth $30,000 to target Iran-linked hackers.
financial $30,000 $ worth
‎summer 2024
Threat actors used hacking tools to gain unauthorized access into the networks of several U.S. government offices in summer 2024.
industry Government
‎February 2026
Iranian threat actors launched a multi-pronged hacking campaign against the US and Israel, targeting over 30 water and wastewater utilities in at least 12 states.
source_region Iran, Islamic Republic of
source_region Israel
attribution the Federal Bureau of Investigation (FBI
general_metric 30 utilities
general_metric 12 U.S. states
organisation SentinelOne
organisation Telegram
organisation DTI
‎2026/07/26
Threat actors used Iranian hackers to target the U.K.
source_region Iran, Islamic Republic of
‎2026/08/18
The U.S. Justice Department sanctioned five individuals linked to Iran-linked hackers in connection with widespread compromises against US entities on or after August 18, 2026.
organisation the U.S. Justice Department
‎August 18
The Department of Justice indicted 17 individuals, including the Mabna Institute, for their involvement in cyber-espionage campaigns targeting critical infrastructure.
tactic Espionage
organisation Mabna Institute
organisation the Department of Justice (DoJ
data_breach 17 members
‎August 20, 2026
General Document Context Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm.
general_metric 10 addresses
general_metric 15.5 addresses
general_metric 92 %
‎August 22, 2026
Iran-linked hackers used Zedcex and Zedxion front companies to facilitate operational financing for the Iranian armed forces branch, with $1 billion in funds linked to IRGC processed through these exchanges.
general_metric 15 wallet addresses
financial $1.2 Mesri
financial $1 exchanges
financial $202,662 addresses
‎August 24
Treasury Secretary Scott Bessent announced Operation Economic Outcast on August 24 to cut financial flows supporting Tehran, targeting entities including Treasury and TRM Labs.
organisation Treasury
campaign Operation Economic Outcast
‎2026/08/25
The US Department of the Treasury announced sanctions on nearly 60 Iran-linked entities, individuals, and vessels across various sectors.
organisation Treasury
organisation MOIS
organisation Operation Economic Outcast
organisation the Islamic Revolutionary Guard Corps
organisation IRGC
organisation the Mabna Institute
organisation OFAC
organisation US Sanctions Mabna Institute Hackers
financial $16.8 members
organisation Iranian Threat Group
organisation Bitcoin, Ethereum
organisation the Treasury Scott Bessent
organisation Mabna Institute
organisation Mabna
financial $15.5 $ Most
financial $1.2 Mesri
organisation HBO
Tactical Metrics
Metrics
financial
30,000
$ Worth
Metrics
financial
1,200,000
Mesri
Metrics
financial
1,000,000,000
Exchanges
Metrics
financial
16,800,000
Members
Metrics
financial
202,662
Addresses
Metrics
victims
42
Based Sector Companies
Metrics
victims
11
Sector Companies
Metrics
data_breach
17
Members
Metrics
financial
15,500,000
$ Most
Intelligence Sources
Infosecurity-Magazine 2026-08-25