Reporting through 2025 describes Iranian state-linked intrusion sets — tracked under designations including APT33, APT34 and MuddyWater — conducting sustained campaigns against Gulf energy companies, aerospace and defence firms, and government agencies. Separately, a group linked to the Islamic Revolutionary Guard Corps has been described as running ransomware operations against critical infrastructure across several countries.
The State-And-Criminal Overlap Is The Notable Part
This corpus separates espionage from extortion because the objectives differ: collection wants access held quietly, extortion wants disruption made visible.
A state-linked group running ransomware collapses that separation. It may be revenue generation, cover for collection, deniable disruption, or all three — and from a defender’s position the distinction is unresolvable in the moment.
The corpus recorded the same collapse from the other direction at 25-0719, where one exploit chain served two espionage sets and a ransomware operation within days. Actor categories describe intent, not capability, and intent is the thing least visible during an incident.
Long-Running Designations Carry An Assumption
APT33 and APT34 have been tracked for years. That longevity gives the names authority, and it should be read carefully: a designation is a cluster of observed tradecraft, maintained by researchers, not an organisation with a stable membership.
This desk’s position at 26-0217 is that tradecraft resemblance is not identification. A decade-old label describes continuity in technique, which may or may not correspond to continuity in people.
The Target List Is Conventional And The More Informative For It
Energy, aerospace, defence and government is the classic state-collection set — capability, intent and industrial capacity. It contains none of the surprises of the list at 25-0725, where lodging appeared alongside telecom and military.
Graded medium: the campaigns are consistently reported across sources, and this desk has no named victims, dates or scope for any of them.
Compiled from published research, listed below. Attribution follows those assessments and is recorded as such. No victims are named and no scope is established. Corrections: corrections@forensicpost.com.
- Firewalls and fault lines: cyber war in the Middle EastLieber Institute, West Point
- Current cyberthreats in the Middle EastPositive Technologies