Monitoring Cyberattacks Directly Linked to the US-Israel-Iran Military Conflict

July 08, 2026

This Flare brief covers confirmed and credibly reported cyber operations over the last 24 hours running July 7 through July 8, 2026, linked to the US-Israel-Iran conflict. The intervening period between reports saw a June 14 memorandum of understanding, signed June 17 by both presidents, intended to terminate hostilities within a 60-day window, followed by a fragile and repeatedly violated interim ceasefire.

The defining development in this window is kinetic, not cyber. On July 7, Iranian forces struck three commercial vessels transiting the Strait of Hormuz off the coast of Oman, including a Qatari LNG tanker and a Saudi-flagged crude tanker. US Central Command responded with a series of strikes on more than 80 Iranian targets, including air defenses, radar sites, anti-ship missile capabilities, and more than 60 IRGC small boats. The US Treasury revoked the waiver that had authorized Iranian oil sales. President Trump stated that the ceasefire is over. The strikes coincided with the multi-day state funeral for Supreme Leader Ali Khamenei, during which mourners publicly called for retaliation against US and Israeli leadership. The UK Maritime Trade Operations Centre raised the Strait of Hormuz threat level to severe.

No new attributed cyber operation falls inside the 24-hour window. The cyber threat picture remains governed by the detection baselines established in April and sustained through the reporting series: DomainTools unified MOIS attribution (Apr 20), CISA AA26-097A PLC advisory (Apr 7), Unit 42 CL-STA-1128 FactoryTalk-on-VPS tradecraft (Apr 17), Check Point Void Manticore TTPs (Apr 2), and FBI FLASH-20260320-001 Telegram C2 malware. The operationally significant change is the collapse of the interim ceasefire and the return to active kinetic exchange, which resets the retaliation clock. Iranian cyber operations across the conflict have consistently been timed to kinetic events. Hold all established detection posture at maximum sensitivity. Treat the resumption of strikes and the public revenge framing around the Khamenei funeral as a probable trigger for a renewed hacktivist surge and for MOIS-directed information operations against US and Gulf targets. This window is an early-warning window, not a post-incident window.

We will continue to update this timeline with the most recent information as the situation develops.

Key Findings – July 7 to July 8, 2026

Key Findings

July 7 to July 8, 2026

No new attributed cyber operation falls inside the 24-hour window; the defining development is kinetic re-escalation. Iran struck three commercial vessels in the Strait of Hormuz on July 7. US Central Command responded with strikes on more than 80 targets. President Trump declared the ceasefire over and the US Treasury revoked the Iranian oil sales waiver. No cyber operation has been publicly attributed inside the window.

CENTCOM, Jul 7; CBS News, Jul 7; NPR, Jul 7; CNBC, Jul 7

Ceasefire collapse resets the retaliation clock; treat this as an early-warning window for a renewed hacktivist surge. Iranian cyber operations across the conflict have been timed to kinetic events. The return to active strikes, paired with public revenge framing around the Khamenei state funeral, is the most probable trigger for renewed DDoS, defacement, hack-and-leak, and MOIS-directed information operations against US and Gulf targets.

CENTCOM, Jul 7; Fox News, Jul 7; historical pattern per Unit 42, Apr 17

CISA AA26-097A and Unit 42 CL-STA-1128 remain the anchoring OT detection baseline. The April 7 joint CISA / FBI / NSA / EPA / DOE / CNMF advisory on Iranian exploitation of Rockwell / Allen-Bradley PLCs across US water, wastewater, energy, and government services remains in effect. Unit 42’s April 17 assessment of CL-STA-1128 FactoryTalk-on-VPS tradecraft remains the active state-aligned OT detection picture. Over 3,000 Rockwell devices remain exposed. No new federal cyber advisory was issued in the window.

CISA AA26-097A, Apr 7; Unit 42, Apr 17

Defenders should treat the resumption of strikes as the trigger condition their playbooks were written for. Hold all established detection posture at maximum sensitivity. Brief personnel and dependents in the CENTCOM area of responsibility on the Handala WhatsApp lure pattern documented in the prior window. Validate offline backup integrity now, while there is operational space. Prepare to validate and respond to breach and leak claims, which historically spike within hours of kinetic escalation.

CENTCOM, Jul 7; Stars and Stripes, Apr 28; Unit 42, Apr 17

For customers seeking further details, please reach out to your Customer Success Manager, and for non-customers please reach out here.

US-Israel-Iran Conflict Timeline & Cyber Context

The cyber operations documented in this brief are responses to three major kinetic escalations:

Kinetic Events & Cyber Response Pattern
Date
Kinetic Event
Cyber Response Pattern

June 13–25, 2025

Israel launches surprise attack on Iranian nuclear / military facilities; US strikes three nuclear sites on June 22

Immediate hacktivist surge; 120+ groups active; DDoS, wiper malware, financial theft, website defacement

January 20–26, 2026

Pre-conflict escalation; large-scale scanning and credential harvesting reported

Attacks on Iranian ports, power substations; Shamoon 4.0 variant strikes Saudi infrastructure

February 28, 2026

US-Israel Operation Epic Fury / Roar of the Lion targeting IRGC, missile sites, and leadership

Largest cyberattack in conflict history; near-total Iranian internet blackout; retaliatory cyber operations active and escalating

June 17, 2026

Memorandum of understanding signed by both presidents; naval blockade lifted; Strait reopening agreed

Reduced public hacktivist output; MOIS persona activity assessed as covert execution rather than dormancy

July 7, 2026

Iran strikes three vessels in Strait of Hormuz; US strikes 80+ targets; ceasefire declared over; oil waiver revoked

No attributed cyber operation yet in window; retaliation probability sharply elevated; early-warning posture

Confirmed & Credibly Reported Cyber Attacks

Note: This update covers the 24-hour window 7 to 8 July 2026. Events from February 28 through May 4, 2026 are tracked in prior revisions. No new attributed cyber operation was publicly reported inside the window. The entries below record the anchoring baselines that remain in force and the kinetic trigger condition that governs the near-term outlook.

No New Attributed Cyber Operation in Window; Kinetic Re-Escalation Is the Governing Event (Jul 7-8, 2026)

  • Threat Actor: Not applicable; no attributed cyber operation in window. Governing event is kinetic (Iranian IRGC maritime strikes; US Central Command retaliatory strikes)
  • Target: Commercial shipping in the Strait of Hormuz (Qatari LNG tanker, Saudi-flagged crude tanker, third tanker off Oman); Iranian air defense, radar, anti-ship missile, and IRGC small-boat assets
  • Attack Type: Kinetic. Iranian projectile and drone strikes on transiting vessels; US precision strikes on more than 80 Iranian targets. No cyber vector attributed in window

On 7 July, three commercial vessels were struck while transiting the Strait of Hormuz off the coast of Oman. Iranian state television indicated at least one vessel was attacked after ignoring warnings, though Tehran did not directly claim the strikes. Qatar and Saudi Arabia condemned attacks on their flagged tankers. US Central Command stated it launched a series of strikes against Iran, hitting more than 80 targets with precision munitions, including air defense systems, command and control networks, coastal radar, anti-ship missile capabilities, and more than 60 IRGC small boats. President Trump, attending the NATO summit in Ankara, approved the strike plan and stated the ceasefire is over. The US Treasury revoked the general license authorizing Iranian oil and petrochemical sales.

No cyber operation has been attributed inside the 24-hour window. This is consistent with the observed sequencing across the conflict, in which cyber activity follows kinetic escalation by hours to days rather than preceding it. The absence of an attributed operation in the window should be read as an early-warning condition, not an all-clear. The Khamenei state funeral, running concurrently, featured public calls for retaliation against US and Israeli leadership, which raises the probability of MOIS-directed information operations and a hacktivist surge in the near term.

Defender takeaway: treat the resumption of strikes as the trigger condition. Move detection and response posture from steady-state to elevated. Prepare to validate and respond to breach and leak claims, which historically appear within hours of kinetic escalation and are frequently exaggerated for psychological effect. Do not wait for an attributed operation to raise posture.

Sources: CENTCOM (Jul 7, 2026); CBS News (Jul 7); NPR (Jul 7); CNBC (Jul 7); Fox News (Jul 7); Al Jazeera (Jul 7); Bloomberg (Jul 7)

CISA AA26-097A and Unit 42 CL-STA-1128 Detection Baselines Hold; No New Federal Cyber Advisory in Window (Jul 7-8, 2026)

  • Threat Actor: IRGC CEC / CyberAv3ngers / CL-STA-1128 / Storm-0784 / Hydro Kitten / Bauxite
  • Target: US water and wastewater systems; energy sector; government services; Rockwell / Allen-Bradley PLC operators; 3,000+ internet-exposed Rockwell devices
  • Attack Type: PLC exploitation; project file manipulation; HMI / SCADA display manipulation; configuration wiping; FactoryTalk-on-VPS tradecraft

The April 7 joint advisory AA26-097A on Iranian-affiliated exploitation of internet-facing Rockwell / Allen-Bradley PLCs across US water, wastewater, energy, and government services remains the anchoring federal OT guidance. No new federal cyber advisory was issued in the 24-hour window. Unit 42’s April 17 assessment that the actor installed Rockwell FactoryTalk software on VPS infrastructure to enable exploitation remains the operative detection picture. The exposure population of internet-facing Rockwell devices, over 3,000 per CISA analysis, has not materially decreased.

The kinetic re-escalation raises the salience of this baseline. OT-focused Iranian actors have historically prioritized water, energy, and government-services targets for their asymmetric and symbolic value during periods of active conflict. Hold PLC detections at maximum sensitivity.

Defender takeaway: keep all Rockwell Automation and Allen-Bradley PLCs and OT devices out of direct internet exposure. Monitor ports 44818, 2222, 102, 22, and 502. Hunt for anomalous FactoryTalk client connections originating from VPS or commercial cloud IP ranges. Flag Studio 5000 Logix Designer sessions from non-engineering-workstation source networks. Verify project file and controller logic integrity. Report suspected compromise to CISA and Rockwell PSIRT.

Sources: CISA AA26-097A (Apr 7, 2026); Unit 42 CL-STA-1128 (Apr 17); EPA joint advisory (Apr 7); CSIS (May 12)

For customers seeking further details, please reach out to your Customer Success Manager, and for non-customers please reach out here.

Key Threat Actor Summaries

Actor Tracker
Actor Affiliation Primary TTPs Key Targets (Window) Confirmation
Handala / Void Manticore / Storm-0842 / Banished Kitten / Dune (unified MOIS persona) Iran MOIS; Panjaki handler WhatsApp / Telegram intimidation; doxxing; BiBi Wiper family; GoXML.exe; cl.exe; Microsoft Intune admin abuse; Telegram Bot API C2 USMC personnel at Naval Support Activity Bahrain (2,379 records); civilian recipients in Israel Stars and Stripes; SecurityWeek; SOCRadar; SAN; DomainTools; DOJ
CyberAv3ngers / Shahid Kaveh / CL-STA-1128 IRGC CEC PLC exploitation; SCADA / HMI manipulation; OT disruption; Studio 5000 project file abuse; FactoryTalk-on-VPS staging US water, energy, government services; Rockwell / Allen-Bradley PLC operators; 3,000+ exposed devices CISA AA26-097A; FBI; NSA; EPA; DOE; CNMF; Unit 42
MuddyWater / Seedworm Iran MOIS Operation Olalampo; CastleRAT; ChainShell blockchain C2; Tsundere botnet US networks; Israeli targets; defense and aerospace sectors JUMPSEC; Broadcom; Recorded Future
Pro-Iranian hacktivist ecosystem (60+ groups) Mixed; Iran-aligned and pro-Russian DDoS; defacement; hack-and-leak; credential harvesting; info ops; ICS / OT access claims US infrastructure; Israeli defense; Gulf states; NATO allies (DDoS tempo at post-April 18 baseline) Industry Telegram monitoring; Unit 42; CrowdStrike; Flashpoint
Pay2Key / Pay2Key.I2P Iran MOIS / Fox Kitten Pseudo-ransomware; destructive encryption; RaaS with 80 percent affiliate share US healthcare; Western critical infrastructure; 170+ victims since Jul 2025 Dark Reading; KELA; Halcyon; FBI / CISA / DoD

Relevant Government Advisories

No new federal cyber advisories issued in the seven-day window. Anchoring guidance below remains in effect:

Government Advisories – July 7 to July 8, 2026
Date
Source
Summary

July 7–8, 2026

Federal cyber agencies

No new federal cyber advisory issued in the window. AA26-097A remains in effect. CISA capacity remains degraded under the DHS shutdown. The DOJ-coordinated domain seizures of Justicehomeland[.]org, Karmabelow80[.]org, Handala-Hack[.]to, and Handala-Redwanted[.]to remain active; reconstitution via successor domains continues. State Department reward for Handala operator identification remains posted.

July 7, 2026

CENTCOM

US Central Command announced a series of strikes on more than 80 Iranian targets in response to Iranian attacks on three commercial vessels in the Strait of Hormuz. President Trump stated the ceasefire is over. US Treasury revoked the Iranian oil sales waiver.

April 20, 2026

DomainTools / GBHackers

Active attribution baseline. DomainTools research unified Homeland Justice, Karma / KarmaBelow80, and Handala as interchangeable skins over a single MOIS-directed operation under the Panjaki handler.

April 17, 2026

Unit 42 (CL-STA-1128)

Iran threat brief. Unit 42 tracks Iranian OT / ICS activity as CL-STA-1128 (overlapping CyberAv3ngers / Storm-0784). Attackers assessed with moderate confidence to have installed Rockwell FactoryTalk software on VPS infrastructure to enable exploitation.

April 7, 2026

CISA AA26-097A (anchoring)

Joint advisory from CISA, FBI, NSA, EPA, DOE, and CNMF on Iranian-affiliated exploitation of internet-facing Rockwell / Allen-Bradley PLCs across US water, wastewater, energy, and government services sectors. Remains the anchoring US government guidance for the current Iranian OT threat.

July 7–8, 2026

Federal cyber agencies

No new federal cyber advisory issued in the window. AA26-097A remains in effect. CISA capacity remains degraded under the DHS shutdown. The DOJ-coordinated domain seizures of Justicehomeland[.]org, Karmabelow80[.]org, Handala-Hack[.]to, and Handala-Redwanted[.]to remain active; reconstitution via successor domains continues. State Department reward for Handala operator identification remains posted.

For historical advisories, please reach out to your Customer Success Manager if you are a customer, and reach out here if you are not a customer.

Assessment & Outlook

The conflict has entered its 66th day. The following assessment reflects cyber developments from the previous seven days.

Near-Term Cyber Threat (1 to 4 weeks): CRITICAL & ELEVATED

The previous seven days produced one attributed cyber operation: the Handala WhatsApp threat campaign against US service members at Naval Support Activity Bahrain on April 27 to 28, paired with a Telegram-channel doxxing post claiming the names and phone numbers of 2,379 US Marines stationed in the Persian Gulf. Identical Persian-themed messages were sent to civilian recipients across Israel on the same day. The genuine signal in the window is the shift from enterprise targets to direct intimidation of named US military personnel and their families.

The cyber threat picture remains governed by the detection baselines established earlier in April: DomainTools unified MOIS attribution, CISA AA26-097A, Unit 42 CL-STA-1128, Check Point Void Manticore, and FBI FLASH-20260320-001. Hacktivist DDoS tempo continues at post-April 18 baseline. The Iran internet blackout at Day 66 sustains the VSAT operational shift picture for state-actor infrastructure. The Bahrain campaign is consistent with the Halcyon thesis that prior quiet periods reflected covert execution rather than dormancy. Iranian retaliation probability against US critical infrastructure, IRGC 18-company target list organizations, Israeli defense and telecom, Gulf government portals, and MSC-adjacent vendors remains elevated. The Bahrain campaign also raises the probability that personnel-targeted information operations will spread from US Navy and Marine Corps personnel to other service branches and to defense-contractor employees with classification or critical-infrastructure roles.

Priority Cyber Targets (Updated for Window)

  • Strait of Hormuz shipping-adjacent and maritime-logistics networks (CRITICAL, NEW IN WINDOW): The maritime strikes make shipping operators, port authorities, flag-state registries, and maritime-logistics vendors a probable near-term target for disruption and information operations.
  • US critical infrastructure with internet-facing Rockwell PLCs and OT devices (CRITICAL, SUSTAINED): CISA AA26-097A remains in effect. Unit 42 CL-STA-1128 FactoryTalk-on-VPS tradecraft remains the active detection picture. Over 3,000 Rockwell devices remain exposed.
  • US military personnel and dependents in CENTCOM AOR (CRITICAL, SUSTAINED): The prior-window Bahrain campaign established the personal-device intimidation pattern. Ceasefire collapse raises the probability of renewed personnel-targeted information operations.
  • Gulf state digital infrastructure (CRITICAL, SUSTAINED): Qatar and Saudi Arabia were directly affected by the maritime strikes. Gulf government portals, energy operators, and airports remain in scope for DDoS and defacement.
  • Israeli defense, telecom, and government (CRITICAL, SUSTAINED): Unified MOIS operation targeting weight sustained against this tier.
  • US critical infrastructure and financial services (CRITICAL, SUSTAINED): Iran has previously declared US financial institutions and major technology companies legitimate targets. Elevated probability under renewed kinetic conditions.

At Flare, we will continue to monitor this conflict and update this article as we learn more information. 

Threat Intelligence

Monitor State-Linked Cyber Threats as They Emerge

The US-Israel-Iran conflict has unleashed a wave of cyber operations spanning hacktivist groups, nation-state APTs, and ransomware affiliates. Flare continuously monitors the dark web, illicit Telegram channels, and threat actor infrastructure so your team can detect and respond to emerging threats before they reach your organization.

Continuous dark web & Telegram channel monitoring
Real-time threat actor tracking & alerting
Start Free Trial

Share article

Related Content

View All
07.21.2026

NULLZEREPTOOL: Inside a Telegram-Controlled DDoS and Multi-Function Attack Framework

07.20.2026

Strengthening Our Commitment to Responsible Threat Intelligence

07.20.2026

Stolen Healthcare Data Exists in the Gap of High-Value PII and Lower Sentences