Desk live·
ForensicPost
Nation-state/Espionage/File 25-0731

Sustained Campaigns Against Energy, Aerospace and Government

Iranian state-linked intrusion sets ran sustained operations against Gulf energy, aerospace and defence firms and government agencies through 2025.

Constructed geometry · not a chart of case data
TargetGulf energy and government
ActorIranian state-linked sets
D. Kennedy12 min readConfidence: medium2 sources reviewed

Reporting through 2025 describes Iranian state-linked intrusion sets — tracked under designations including APT33, APT34 and MuddyWater — conducting sustained campaigns against Gulf energy companies, aerospace and defence firms, and government agencies. Separately, a group linked to the Islamic Revolutionary Guard Corps has been described as running ransomware operations against critical infrastructure across several countries.

The State-And-Criminal Overlap Is The Notable Part

This corpus separates espionage from extortion because the objectives differ: collection wants access held quietly, extortion wants disruption made visible.

A state-linked group running ransomware collapses that separation. It may be revenue generation, cover for collection, deniable disruption, or all three — and from a defender’s position the distinction is unresolvable in the moment.

The corpus recorded the same collapse from the other direction at 25-0719, where one exploit chain served two espionage sets and a ransomware operation within days. Actor categories describe intent, not capability, and intent is the thing least visible during an incident.

Long-Running Designations Carry An Assumption

APT33 and APT34 have been tracked for years. That longevity gives the names authority, and it should be read carefully: a designation is a cluster of observed tradecraft, maintained by researchers, not an organisation with a stable membership.

This desk’s position at 26-0217 is that tradecraft resemblance is not identification. A decade-old label describes continuity in technique, which may or may not correspond to continuity in people.

The Target List Is Conventional And The More Informative For It

Energy, aerospace, defence and government is the classic state-collection set — capability, intent and industrial capacity. It contains none of the surprises of the list at 25-0725, where lodging appeared alongside telecom and military.

Graded medium: the campaigns are consistently reported across sources, and this desk has no named victims, dates or scope for any of them.

How we reported this

Compiled from published research, listed below. Attribution follows those assessments and is recorded as such. No victims are named and no scope is established. Corrections: corrections@forensicpost.com.

Sources
  1. Firewalls and fault lines: cyber war in the Middle EastLieber Institute, West Point
  2. Current cyberthreats in the Middle EastPositive Technologies
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary